Sensitive information sent insecurely In requests
Description
Requests vulnerable to .netrc credentials leak via malicious URLs
Impact
Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.
Workarounds
For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs).
References
https://github.com/psf/requests/pull/6965 https://seclists.org/fulldisclosure/2025/Jun/2
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.19 | 2.32.4-r0 | ||
debian 14 | 2.32.4+dfsg-1 | ||
alpine v3.20 | 2.32.4-r0 | ||
alpine v3.21 | 2.32.4-r0 | ||
alpine v3.22 | 2.32.4-r0 | ||
debian 11 | - | ||
debian 12 | - | ||
debian 13 | 2.32.3+dfsg-5+deb13u1 | ||
pypi | 2.32.4 | ||
alpine v3.23 | 2.32.4-r0 |
1-10 of 23
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.