Sourced from gunicorn's releases.
gunicorn 26.2.0
Cleartext HTTP/2 lands, and an HTTP/2 security fix.
Cleartext HTTP/2 (h2c)
http2_cleartextacceptsprior-knowledge,upgrade,bothoroff(the default). Prior knowledge serves a connection that opens with the HTTP/2 preface;upgradehonours an HTTP/1.1Upgrade: h2crequest. Both work on the gthread, gevent and asgi workers.This is for deployments where TLS is terminated by a proxy that speaks HTTP/2 upstream, so the hop into gunicorn no longer drops to HTTP/1.1. Only peers in
forwarded_allow_ipsare considered; everyone else is served HTTP/1.x exactly as if the setting were off. Each mechanism is enabled separately, so turning one on does not turn the other on.Do not expose a cleartext HTTP/2 port to the internet.
Security
HTTP2Requestbuilt its headers straight from the stream, so nothing the HTTP/1 path enforces applied over HTTP/2: the underscore andheader_mappolicy, duplicateHostandContent-Type, control characters in values, and theforwarded_allow_ipstrust gate. An untrusted client could setSCRIPT_NAMEand forgeHTTP_*entries in the WSGI environ, and decidewsgi.url_schemethrough:scheme. Both request classes now share one policy mixin, and the scheme comes from the transport.If you serve HTTP/2, this is the reason to upgrade.
Other HTTP/2 fixes
WSGI responses were buffered whole before anything was sent; they stream now. HEAD, 204 and 304 no longer carry a body. Events read while blocked on a flow-control window were discarded, losing requests and body data outright.
sendfile()is refused on HTTP/2 responses rather than bypassing framing.Request bodies dropped on Upgrade requests
On the ASGI worker with the fast parser, any request carrying an
Upgradeheader reached the application with an empty body, whatever the header's value and with HTTP/2 switched off entirely. Fixed ingunicorn_h1c0.6.9, which thefastextra now requires.Full changelog: https://gunicorn.org/news/
36f2a3c
gunicorn 26.2.0cbba350
test: cover the h2c edge paths that had none9885411
Merge pull request #3703
from cormier/fix-inconsistency-in-control-socket-docs86f0919
Merge pull request #3704
from methane/doc-wsgi-h1c5853551
Merge pull request #3712
from Rotzbua/patch-17bce87e
Merge pull request #3700
from benoitc/fix/sponsor-logo-path972dfb0
Merge pull request #3690
from melbinjp/docs/contributing-settings-path7b3f16b
Merge pull request #3711
from benoitc/docs/http2-changelog5bf237c
http2: require gunicorn_h1c 0.6.9 and drop the upgrade body
workaround7cf0338
test: skip the fast-parser cases when gunicorn_h1c is absentSourced from seleniumbase's releases.
4.52.3 - MCP Server: Patch 1
MCP Server: Patch 1
- Fix the MCP Server on Python versions less than 3.14 --> This resolves seleniumbase/SeleniumBase#4471 --> (Due to this bug, the MCP Server only worked on Python 3.14+) --> (Caused by a missing line:
from __future__ import annotations)- Update logging messages
- Update the docs for MCP servers
- Refresh Python dependencies
- Update examples
What's Changed
- MCP Server: Patch 1 by
@​mdmintzin seleniumbase/SeleniumBase#4472Full Changelog: https://github.com/seleniumbase/SeleniumBase/compare/v4.52.2...v4.52.3
9112244
Merge pull request #4472
from seleniumbase/mcp-server-patch-1bf1abf6
Version 4.52.3405c7c6
Update examples2135803
Refresh Python dependencies1584e5b
Update the docs for MCP servers0e14a09
Update logging messages9bdc113
Fix the MCP Server on Python versions less than 3.14cbd624a
Update the docs