{"record":{"id":"4233027a71399f37","repo":"pypa/pip","slug":"unexpected-http-request-on-what-should-be-a-secure","errorCode":null,"errorMessage":"Unexpected HTTP request on what should be a secure connection: %s","messagePattern":"Unexpected HTTP request on what should be a secure connection: (.+?)","errorType":"exception","errorClass":"URLError","httpStatus":null,"severity":"error","filePath":"src/pip/_vendor/distlib/util.py","lineNumber":1559,"sourceCode":"                if 'certificate verify failed' in str(e.reason):\n                    raise CertificateError('Unable to verify server certificate '\n                                           'for %s' % req.host)\n                else:\n                    raise\n\n    #\n    # To prevent against mixing HTTP traffic with HTTPS (examples: A Man-In-The-\n    # Middle proxy using HTTP listens on port 443, or an index mistakenly serves\n    # HTML containing a http://xyz link when it should be https://xyz),\n    # you can use the following handler class, which does not allow HTTP traffic.\n    #\n    # It works by inheriting from HTTPHandler - so build_opener won't add a\n    # handler for HTTP itself.\n    #\n    class HTTPSOnlyHandler(HTTPSHandler, HTTPHandler):\n\n        def http_open(self, req):\n            raise URLError('Unexpected HTTP request on what should be a secure '\n                           'connection: %s' % req)\n\n\n#\n# XML-RPC with timeouts\n#\nclass Transport(xmlrpclib.Transport):\n\n    def __init__(self, timeout, use_datetime=0):\n        self.timeout = timeout\n        xmlrpclib.Transport.__init__(self, use_datetime)\n\n    def make_connection(self, host):\n        h, eh, x509 = self.get_host_info(host)\n        if not self._connection or host != self._connection[0]:\n            self._extra_headers = eh\n            self._connection = host, httplib.HTTPConnection(h)\n        return self._connection[1]","sourceCodeStart":1541,"sourceCodeEnd":1577,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_vendor/distlib/util.py#L1541-L1577","documentation":"Raised by distlib's HTTPSOnlyHandler.http_open. This handler class inherits from both HTTPSHandler and HTTPHandler so that build_opener does not register its own plain-HTTP handler; instead, every plain http:// request is intercepted and rejected. This prevents accidental HTTP traffic (and MITM downgrade attacks) on a connection intended to be HTTPS-only, e.g. when an index page contains an http:// link where an https:// link was expected.","triggerScenarios":"Building a URL opener with HTTPSOnlyHandler and then requesting a URL with an http:// scheme, or following a redirect/link from an HTTPS index page that points to a plain HTTP URL.","commonSituations":"A PyPI index serves HTML with http:// links by mistake; a redirect chain degrades from https to http; developer accidentally passes an http:// URL where https:// was intended; corporate proxy strips TLS and serves plain HTTP.","solutions":["Ensure all URLs in your configuration use the https:// scheme.","If the source is an index page, fix the server to serve https:// links.","Verify no redirect in the chain downgrades from HTTPS to HTTP.","If plain HTTP is genuinely required for this endpoint, use HTTPSHandler instead of HTTPSOnlyHandler (accepting the security trade-off)."],"exampleFix":"# before — plain HTTP URL rejected\nopener = build_opener(HTTPSOnlyHandler(...))\nopener.open('http://pypi.org/simple/')  # raises\n\n# after — use HTTPS\nopener.open('https://pypi.org/simple/')","handlingStrategy":"validation","validationCode":"from urllib.parse import urlsplit\n\ndef ensure_https(url):\n    parts = urlsplit(url)\n    if parts.scheme != 'https':\n        raise ValueError(f'Expected https:// URL, got {parts.scheme}:// for {url}')\n    return url","typeGuard":null,"tryCatchPattern":"from urllib.error import URLError\ntry:\n    opener.open(url)\nexcept URLError as e:\n    if 'Unexpected HTTP request' in str(e):\n        log.error('HTTP URL used on HTTPS-only handler: %s', url)\n    raise","preventionTips":["Normalize all URLs to https:// at the application boundary.","Validate URL scheme before passing to an HTTPSOnlyHandler opener.","Audit index page HTML for http:// links in your infrastructure."],"tags":["security","network","https","mitm"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}