mirror of https://github.com/vee1e/mitmproxy - An interactive TLS-capable intercepting HTTP proxy for penet
Find a file
Gaurav Dubey f384cb7401
net.tls: handle SSL.Error from set_min/max_proto_version in is_supported_version (#8294)
* net.tls: handle SSL.Error from set_min/max_proto_version in is_supported_version

is_supported_version() built an SSL.Context, set the min/max protocol
version, then probed support with client_conn.recv(). Only the recv()
probe was wrapped in try/except SSL.Error.

On OpenSSL builds that have dropped a protocol version entirely (e.g.
SSLv3 after POODLE / CVE-2014-3566, see pyca/cryptography#9523),
set_min_proto_version(SSL3_VERSION) raises SSL.Error already at
context-setup time, before the guarded recv(). The exception then
propagated unhandled and crashed callers such as
TlsConfig._warn_unsupported_version, which iterates over every Version to
build the "supported versions" list.

Move the protocol-version setters and connection setup inside the
existing try, so a setup-time SSL.Error is treated the same as a
probe-time one: the version is reported as unsupported (return False)
instead of raising. Behavior for currently-supported versions is
unchanged.

Add a regression test that monkeypatches SSL.Context.set_min_proto_version
to raise SSL.Error, reproducing the crash path deterministically on any
OpenSSL build, and clear the is_supported_version LRU cache around it.

Closes #8264

* Remove test for SSL context setup error handling

---------

Co-authored-by: Maximilian Hils <git@maximilianhils.com>
2026-08-20 22:57:26 +00:00
.github build(deps): bump the github-actions group with 16 updates (#8389) 2026-08-20 22:43:37 +00:00
docs build(deps-dev): bump ruff from 0.15.11 to 0.16.3 (#8386) 2026-08-20 22:47:00 +00:00
examples Fix IP blocking and merge additional DoH blocklists (#8197) 2026-04-28 20:25:50 +02:00
mitmproxy net.tls: handle SSL.Error from set_min/max_proto_version in is_supported_version (#8294) 2026-08-20 22:57:26 +00:00
release docs: fix typos (#8285) 2026-06-18 08:51:03 +02:00
test fix: replace deprecated pyparsing API aliases with snake_case equivalents (#8344) 2026-08-08 08:07:53 +02:00
web mitmweb: use SVG icons for flow table resource types (#8337) 2026-08-04 16:29:59 +02:00
.gitattributes
.gitignore
.python-version Update to Python 3.14 (#7918) 2025-10-15 21:32:53 +02:00
AGENTS.md Add AGENTS.md (#7907) 2025-10-09 20:20:57 +02:00
CHANGELOG.md net.tls: handle SSL.Error from set_min/max_proto_version in is_supported_version (#8294) 2026-08-20 22:57:26 +00:00
codecov.yml
CONTRIBUTING.md
LICENSE
MANIFEST.in
pyproject.toml build(deps-dev): bump the deploy group with 2 updates (#8384) 2026-08-21 00:48:15 +02:00
README.md remove codacy badge 2026-04-12 23:27:13 +02:00
SECURITY.md SECURITY.md: Exclude DoS from scope (#8171) 2026-04-12 22:36:48 +02:00
uv.lock build(deps-dev): bump the deploy group with 2 updates (#8384) 2026-08-21 00:48:15 +02:00

mitmproxy

Continuous Integration Status autofix.ci: enabled Coverage Status Latest Version Supported Python versions

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy with a console interface for HTTP/1, HTTP/2, and WebSockets.

mitmdump is the command-line version of mitmproxy. Think tcpdump for HTTP.

mitmweb is a web-based interface for mitmproxy.

Installation

The installation instructions are here. If you want to install from source, see CONTRIBUTING.md.

Documentation & Help

General information, tutorials, and precompiled binaries can be found on the mitmproxy website.

mitmproxy.org

The documentation for mitmproxy is available on our website:

mitmproxy documentation stable mitmproxy documentation dev

If you have questions on how to use mitmproxy, please use GitHub Discussions!

mitmproxy discussions

Contributing

As an open source project, mitmproxy welcomes contributions of all forms.

Dev Guide