Your message dated Sat, 24 Jan 2026 11:34:51 +0000
with message-id <[email protected]>
and subject line Bug#1126002: fixed in python-urllib3 1.26.12-1+deb12u3
has caused the Debian Bug report #1126002,
regarding python-urllib3: Regression from CVE-2026-21441 fix in bookworm
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1126002: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1126002
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-urllib3
Version: 1.26.12-1+deb12u2
Severity: important
X-Debbugs-Cc: [email protected], [email protected]

Control: affects -1 + release.debian.org,security.debian.org
Control: tags -1 + bookworm

This is to document a regression caused by a broken backport of
CVE-2026-21441 fix vin bookworm:

$ python3 -c 'import urllib3; resp=urllib3.HTTPResponse(); resp.drain_conn()'
Traceback (most recent call last):
  File "<string>", line 1, in <module>
  File "/usr/lib/python3/dist-packages/urllib3/response.py", line 307, in 
drain_conn
    decode_content=self._has_decoded_content,
                   ^^^^^^^^^^^^^^^^^^^^^^^^^
AttributeError: 'HTTPResponse' object has no attribute '_has_decoded_content'. 
Did you mean: 'decode_content'?

There is an upcoming regression fix.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: python-urllib3
Source-Version: 1.26.12-1+deb12u3
Done: Salvatore Bonaccorso <[email protected]>

We believe that the bug you reported is fixed in the latest version of
python-urllib3, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated python-urllib3 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 20 Jan 2026 22:34:53 +0100
Source: python-urllib3
Architecture: source
Version: 1.26.12-1+deb12u3
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Python Team <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1126002
Changes:
 python-urllib3 (1.26.12-1+deb12u3) bookworm-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Prevent issue in HTTPResponse().read() when decoded_content is True and 
then
     False Provided it has initialized eligible decoder(decompressor) and did
     decode once (Closes: #1126002)
   * fix missed coverage when calling read() having amt=None
   * tests: Change expectations as the initial payload changed
Checksums-Sha1:
 d0da29c2f0ad644e4e8279beda93c335d9d60a0b 2499 
python-urllib3_1.26.12-1+deb12u3.dsc
 ad6bd811a3f4c3e04d86c2706c9994c3e2236e53 299806 
python-urllib3_1.26.12.orig.tar.gz
 a413a9461bebcb57313d5339781cfb81a9443524 20140 
python-urllib3_1.26.12-1+deb12u3.debian.tar.xz
 84cb5f9cb4a137bdb5660f08f172762ccc3d98b3 7306 
python-urllib3_1.26.12-1+deb12u3_source.buildinfo
Checksums-Sha256:
 90903b9264067790fa58239bc10cc84d0cdc9e889a51d39663bf104f6de530f0 2499 
python-urllib3_1.26.12-1+deb12u3.dsc
 3fa96cf423e6987997fc326ae8df396db2a8b7c667747d47ddd8ecba91f4a74e 299806 
python-urllib3_1.26.12.orig.tar.gz
 d0673891401721305fec795b7df8c0fc1ea1bb5f349766a61f4f7e2a454df09f 20140 
python-urllib3_1.26.12-1+deb12u3.debian.tar.xz
 64d890a7f6605fb9b4228a0269e6bf6d56fbb28b4c2b3ec6d864d162d93acfb1 7306 
python-urllib3_1.26.12-1+deb12u3_source.buildinfo
Files:
 0bb5ca622dbd8d9a5c74fe484c926a35 2499 python optional 
python-urllib3_1.26.12-1+deb12u3.dsc
 ba308b52b9092184cf4905bc59a88fc0 299806 python optional 
python-urllib3_1.26.12.orig.tar.gz
 db1331c7728638a4f96e13fcb48236a2 20140 python optional 
python-urllib3_1.26.12-1+deb12u3.debian.tar.xz
 ca74243356d6d58972575b73aba13d2f 7306 python optional 
python-urllib3_1.26.12-1+deb12u3_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmlwwORfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ETRAP/A/e0/+7KH9DxQtfVqtbLoUaND+kJDMS
46PrdFo94SMh8+VfN2Q+vaUo6WC7rzXVvzJNTF0H3zKYZqT7ef10Ft7Ld/YUIlYR
Xy15AkCL4uqTmY1pa56Xw8wECIXIfEi/PR4U7+MjKd/FhZjpjLQPnJFzpeVZ7WEp
u5APt3V8Dw2vOvALZSxl5Fj7lAFGajYKXv0diqgIZ6irqQqiXSKDlTbo5JxgPTxu
xvsimRzghQeOjilxec4+Kqfc7agYeNbn2brbFxqT8Pt0mWeCJbgYtJjRuKUD1wku
LJ3puKWM0YHCVr2SxvHFk/oWUNL+QUKKHEMjWyEc8WJCren1kcwBzGhO1oPtDswz
TlSCEgAsr0QutO2BUZzTupbz8YtO/Kyy53B3UvneEZmGI/6aEI9lY81A/Qk0LcVY
EjabMxW3vHP3p0igjxIMfiZ37mqFrtec2SPqsU2SUdjcWmgJrhTMD/wIQs0UD4Uc
KNir8i7FezqOtof2hscMIzQogWBFl3wVTo4C3aGnl7qRch1X1pp4x+X7Q3UjXmyh
gHNj02j6FuO9KZfBrf5LgP2XJDR2R+GEmRKRfplwMHqm5utlkrsGxy+VLBWtzMsZ
iqmIPmTvAsK430EkzGUaHWyo09PYONDmNZpYwBol6Xdnh0E960wcA/8BhpX+NJI6
6+Tf1dm6sWOG
=G2EZ
-----END PGP SIGNATURE-----

Attachment: pgp8lxdmIGKbu.pgp
Description: PGP signature


--- End Message ---

Reply via email to