Skip to content

🟡 [SCA] GHSA-9hjg-9r4m-mvj7 (1 occurrence) #423

@test-recette-alpha

Description

@test-recette-alpha

🔐 Security Vulnerabilities Detected by CybeDefend

1 occurrence(s) of GHSA-9hjg-9r4m-mvj7 detected.

Highest Severity: 🟡 MEDIUM

Description

Impact

Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.

Workarounds

For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs).

References

psf/requests#6965
https://seclists.org/fulldisclosure/2025/Jun/2

Affected Locations

requests@>=0.0.0

  • Unknown line - 🟡 MEDIUM - View

This issue was automatically created by CybeDefend

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions