© 2025-2026 PySpect
First version without a known vulnerability: 2.33.0
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Fixed in: 2.33.0
Requests vulnerable to .netrc credentials leak via malicious URLs
Fixed in: 2.32.4
Requests `Session` object does not verify requests after making first request with verify=False
Fixed in: 2.32.0
Unintended leak of Proxy-Authorization header in requests
Fixed in: 2.31.0, 74ea7cf7a6a27a4eeb2ae24e162bcc942a6706d5
Exposure of Sensitive Information to an Unauthorized Actor in Requests
Fixed in: 2.3.0
Exposure of Sensitive Information to an Unauthorized Actor in Requests
Fixed in: 2.3.0
Python Requests Session Fixation
Fixed in: 2.6.0, 3bd8afbff29e50b38f889b2f688785a669b9aafc
Insufficiently Protected Credentials in Requests
Fixed in: 2.20.0, c45d7c49ea75133e52ab22a8e9e13173938e36ff