Repository navigation
urllib3 pinned to <2.4.0 breaks packaging #2458
Description
Activity
- addedkind/bugCategorizes issue or PR as related to a bug.Categorizes issue or PR as related to a bug.
on Sep 30, 2025 urllib3 versions < 2.5.0 have the following known CVEs:
Pinning urllib3 to < 2.4.0 also prevents users taking a version which addresses these CVEs.
Reacted by Yashvardhan Nanavati, Luke Hsiao, Cole Murray, Shmuel Kroizer, mic-mikolajczyk, Marius, saprette and Calvin TaylorIs
urllib3 >= 2.5.0support planned?For reference, these are some of the issues that motivated the original constraint: #2394
@roycaihw:
This request has been marked as needing help from a contributor.Guidelines
Please ensure that the issue body includes answers to the following questions:
- Why are we solving this issue?
- To address this issue, are there any code changes? If there are code changes, what needs to be done in the code and what places can the assignee treat as reference points?
- How can the assignee reach out to you for help?
For more details on the requirements of such an issue, please see here and ensure that they are met.
If this request no longer meets these requirements, the label can be removed
by commenting with the/remove-helpcommand.Details
In response to this:
@Tenzer Based on the description in #2417, could you check if there is a good urllib3 version that is greater than 2.4.0?
/help
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.
- addedhelp wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
on Oct 9, 2025 @Tenzer Based on the description in #2417, could you check if there is a good urllib3 version that is greater than 2.4.0?
The only more recent urllib3 release, v2.5.0, does not back down on the increased security stance, and I don't imagine it's something they would want to do, since they specifically made the change in v2.4.0 to align with what Python 3.13 does.
In the original discussion about the urllib3 v2.4.0 issue, I suggested that an alternative way to address this could be to add an option to easily disable the extra strictness in urllib3: #2394 (comment). Perhaps that's an option worth investigating, so the maximum urllib3 version can be removed?
As far as I understand, urllib3 2.4 and above only breaks an edge-case scenario. Could we maybe remove the upper version constraint and instead let those affected pin urllib3 on their side?
Reacted by Tyler, Andrew Conti and Jonas Lundholm BertelsenSounds good to me. There's also the workaround mentioned in #2394 (comment) for disabling the SSL verification for people who are affected.
Solved in #2461
We still need a release to get the solution. When is the next anticipated release?
Reacted by NadhiyaPM, Seroney Matoke, lexual-anz, Alessandro Pomponio, gy-gl, Seth Grover, Jan Peter, Swaraj Pande, Joshua Cold, Andrew Conti and 6 moreJust bumping this to see when a release might happen, since this is blocking work/releases for other projects. Thanks.
Reacted by Lqn, Alessandro Pomponio, MatsLP, Tim62556 and tionichmJust another bumping this to see when a release might happen, since this is blocking work/releases for other projects. Thanks.
3 remaining items
I wonder when it will be released...
Hi! When could we expect a new release? Thanks.
/help
Now we need to allow 2.6.x as well due to two new high-severity CVEs:
There are also some more minor ones:
@gpupuck I don't have more info than: #2482 (comment)
Reacted by Brian Yang- added a commit that references this issue
on Aug 3, 2026 This looks resolved.
masternow hasurllib3>=2.7.0,<3.0.0inrequirements.txt(andurllib3>=2.7.0inrequirements-asyncio.txt), and the released 36.0.3 on PyPI requiresurllib3!=2.6.0,>=1.24.2— the<2.4.0cap is gone both in the tree and in a release.@jmontleon does that cover the packaging problem on your side?
@yliaog I think this one can be closed.
thanks @yurnov
/close
kubernetes-prow commented
on Aug 16, 2026 ContributorMore actions@yliaog: Closing this issue.
Details
In response to this:
thanks @yurnov
/close
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.
Is there a more permanent solution to the issues with python 2.4.0+ pending?
https://github.com/kubernetes-client/python/blob/master/requirements.txt#L10
https://bodhi.fedoraproject.org/updates/FEDORA-2025-34e5603fe3
Fedora 43+ has moved to urllib3 2.5.0 so in order to continue packaging the python kubernetes-client will mean carrying a patch to revert this change.