{"schema_version":1,"title":"requests (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in requests (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-47081, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/requests","json_url":"https://junglewise.ai/threats/technologies/requests.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/requests","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":8,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":3},"latest":[{"cve":"CVE-2024-47081","cvss":3.1,"epss":0.0098,"slug":"cve-2024-47081-requests-vulnerable-to-netrc-credentials-leak-via-malicious-urls","title":"PYSEC-2026-1872 - Requests vulnerable to .netrc credentials leak via malicious URLs","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.151964+00:00","url":"https://junglewise.ai/threats/cve-2024-47081-requests-vulnerable-to-netrc-credentials-leak-via-malicious-urls"},{"cve":"CVE-2024-35195","cvss":3.1,"epss":0.0034,"slug":"cve-2024-35195-requests-session-object-does-not-verify-requests-after-making","title":"PYSEC-2026-1873 - Requests `Session` object does not verify requests after making first request with verify=False","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:42.890131+00:00","url":"https://junglewise.ai/threats/cve-2024-35195-requests-session-object-does-not-verify-requests-after-making"},{"cve":"CVE-2026-25645","cvss":3.1,"epss":0.0019,"slug":"cve-2026-25645-requests-has-insecure-temp-file-reuse-in-its-extract-zipped-paths","title":"PYSEC-2026-2275 - Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filenam","severity":"low","exploited":false,"published_at":"2026-03-25T17:16:52.97+00:00","url":"https://junglewise.ai/threats/cve-2026-25645-requests-has-insecure-temp-file-reuse-in-its-extract-zipped-paths"},{"cve":"CVE-2023-32681","cvss":3.1,"epss":0.0297,"slug":"cve-2023-32681-unintended-leak-of-proxy-authorization-header-in-requests","title":"PYSEC-2023-74 - Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirect","severity":"low","exploited":false,"published_at":"2023-05-26T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32681-unintended-leak-of-proxy-authorization-header-in-requests"},{"cve":"CVE-2018-18074","cvss":3.1,"epss":0.0744,"slug":"cve-2018-18074-insufficiently-protected-credentials-in-requests","title":"PYSEC-2018-28 - The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http","severity":"low","exploited":false,"published_at":"2018-10-09T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-18074-insufficiently-protected-credentials-in-requests"},{"cve":"CVE-2015-2296","epss":0.0342,"slug":"cve-2015-2296-python-requests-session-fixation","title":"PYSEC-2015-17 - The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks vi","severity":"info","exploited":false,"published_at":"2015-03-18T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-2296-python-requests-session-fixation"},{"cve":"CVE-2014-1830","cvss":4,"epss":0.0204,"slug":"cve-2014-1830-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2014-14 - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header","severity":"medium","exploited":false,"published_at":"2014-10-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1830-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2014-1829","cvss":3.1,"epss":0.022,"slug":"cve-2014-1829-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2014-13 - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redire","severity":"low","exploited":false,"published_at":"2014-10-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1829-exposure-of-sensitive-information-to-an-unauthorized-actor-in"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"requests (PyPI)","slug":"requests","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/requests"},"most_severe":[{"cve":"CVE-2014-1830","cvss":4,"epss":0.0204,"slug":"cve-2014-1830-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2014-14 - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header","severity":"medium","exploited":false,"published_at":"2014-10-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1830-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2018-18074","cvss":3.1,"epss":0.0744,"slug":"cve-2018-18074-insufficiently-protected-credentials-in-requests","title":"PYSEC-2018-28 - The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http","severity":"low","exploited":false,"published_at":"2018-10-09T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-18074-insufficiently-protected-credentials-in-requests"},{"cve":"CVE-2023-32681","cvss":3.1,"epss":0.0297,"slug":"cve-2023-32681-unintended-leak-of-proxy-authorization-header-in-requests","title":"PYSEC-2023-74 - Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirect","severity":"low","exploited":false,"published_at":"2023-05-26T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32681-unintended-leak-of-proxy-authorization-header-in-requests"},{"cve":"CVE-2014-1829","cvss":3.1,"epss":0.022,"slug":"cve-2014-1829-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2014-13 - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redire","severity":"low","exploited":false,"published_at":"2014-10-15T14:55:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1829-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2024-47081","cvss":3.1,"epss":0.0098,"slug":"cve-2024-47081-requests-vulnerable-to-netrc-credentials-leak-via-malicious-urls","title":"PYSEC-2026-1872 - Requests vulnerable to .netrc credentials leak via malicious URLs","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.151964+00:00","url":"https://junglewise.ai/threats/cve-2024-47081-requests-vulnerable-to-netrc-credentials-leak-via-malicious-urls"},{"cve":"CVE-2024-35195","cvss":3.1,"epss":0.0034,"slug":"cve-2024-35195-requests-session-object-does-not-verify-requests-after-making","title":"PYSEC-2026-1873 - Requests `Session` object does not verify requests after making first request with verify=False","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:42.890131+00:00","url":"https://junglewise.ai/threats/cve-2024-35195-requests-session-object-does-not-verify-requests-after-making"},{"cve":"CVE-2026-25645","cvss":3.1,"epss":0.0019,"slug":"cve-2026-25645-requests-has-insecure-temp-file-reuse-in-its-extract-zipped-paths","title":"PYSEC-2026-2275 - Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filenam","severity":"low","exploited":false,"published_at":"2026-03-25T17:16:52.97+00:00","url":"https://junglewise.ai/threats/cve-2026-25645-requests-has-insecure-temp-file-reuse-in-its-extract-zipped-paths"},{"cve":"CVE-2015-2296","epss":0.0342,"slug":"cve-2015-2296-python-requests-session-fixation","title":"PYSEC-2015-17 - The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks vi","severity":"info","exploited":false,"published_at":"2015-03-18T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-2296-python-requests-session-fixation"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}