Package: python3-urllib3
Version: 2.5.0-1
Severity: important
Forwarded: https://github.com/urllib3/urllib3/issues/3734

Hi,

I'm filing as important because I'm not sure how widely the problem is.
There's apparently an issue in urllib < 2.6.2 with brotli >= 1.2.0

I have python3-brotlicffi installed (because of a calibre dependency)
and it is at version 1.2.0 while python3-brotcli is still at 1.1.0 (see
below), and it seems to trigger the bug.

There's an upstream issue at
https://github.com/urllib3/urllib3/issues/3734 which is apparently fixed
in 2.6.2, if you could update it in Debian?

Note: I'm not sure why the bug wasn't filed and fixed in brotcli, I'm
merely forwarding the upstream bug here :/

Regards,
-- 
Yves-Alexis

-- System Information:
Debian Release: forky/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'unstable'), (500, 'testing'), 
(450, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.17.9+deb14-amd64 (SMP w/14 CPU threads; PREEMPT)
Kernel taint flags: TAINT_WARN
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages python3-urllib3 depends on:
ii  python3  3.13.9-2

Versions of packages python3-urllib3 recommends:
ii  ca-certificates  20250419

Versions of packages python3-urllib3 suggests:
ii  python3-brotli        1.1.0-2+b9
ii  python3-cryptography  46.0.1-1
ii  python3-idna          3.10-1
ii  python3-openssl       25.3.0-1
ii  python3-socks         1.7.1+dfsg-1

-- no debconf information

Reply via email to