Bump mitmproxy from 11.0.0 to 11.1.2
Bumps mitmproxy from 11.0.0 to 11.1.2.
Release notes
Sourced from mitmproxy's releases.
mitmproxy 11.1.2
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
mitmproxy 11.1.0
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
mitmproxy 11.0.2
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
mitmproxy 11.0.1
Changes: See CHANGELOG.md.
You can find the latest release packages at https://mitmproxy.org/downloads/.
Changelog
Sourced from mitmproxy's changelog.
06 February 2025: mitmproxy 11.1.2
- CVE-2025-23217: mitmweb's API now requires an authentication token by default. The mitmweb API is bound to localhost only, but
@gronkefound that an attacker can circumvent that restriction by tunneling requests through the proxy server itself in an SSRF-style attack. (fa89055,@mhils)- Add (optional) password protection for mitmweb. The
web_passwordoption replaces the randomly-generated token authentication with a fixed secret that survives mitmproxy restarts. (0bd573a,@mhils)- mitmweb can now be hosted under arbitrary domains, the previously-used DNS rebind protection is not required anymore. (62693af,
@mhils)- Security Hardening: mitmweb's
xsrf_tokencookie is nowHttpOnly; SameSite=Strict. (#7491,@mhils)- We now provide standalone binaries for Linux arm64. (#7484,
@mhils)- Standalone binaries are now compiled with Python 3.13. (#7485,
@mhils)- Fix console freezing due to DNS queries with an empty question section. (#7497,
@sujaldev)- Add mitmweb tutorial to docs. (#7509,
@EstherRoeth)- Fixed a bug that caused mitmproxy to crash when loading prior knowledge h2 flows. (#7514,
@sujaldev)- Fix a bug where mitmproxy would get stuck in secure web proxy mode when using
ignore_hostsorallow_hosts. (#7519,@mhils)- Copy request/response data to the clipboard in mitmweb (#7352,
@lups2000)- Fix a bug where exporting a curl or httpie command with escaped characters would lead to different data being sent. (#7520,
@proteusvacuum)05 February 2025: mitmproxy 11.1.1
- Yanked. Identical to 11.1.2, but failed to deploy in CI.
12 January 2025: mitmproxy 11.1.0
- Local Capture Mode is now available on Linux as well. (#7440,
@mhils)- mitmproxy now requires Python 3.12 or above. (#7440,
@mhils)- Add cache-busting for mitmweb's front end code. (#7386,
@mhils)- Clicking the URL in mitmweb now places the cursor at the current position instead of selecting the entire URL. (#7385,
@lups2000)- Add missing status codes (#7455,
@jwadolowski)- All filter expressions are now case-insensitive by default. Users can opt into case-sensitive filters by setting MITMPROXY_CASE_SENSITIVE_FILTERS=1 as an environment variable.
... (truncated)
Commits
01490b6mitmproxy 11.1.2aa12372work around cloudflare bugsdced5fbreopen main for developmentabf8ecamitmproxy 11.1.15a135dfupdate CHANGELOG62693afweb: remove dns rebinding protection0bd573aweb: add password-based authenticationfa89055web: add token-based authentication for the web ui APIea0dcb0Update bug report template to use form (#7535)385800fweb: copy request/response data to clipboard (#7352)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.