Compare commits
base: repos:0b2cf11c6a62310c5843f31e9bafe8a1b6f5666b
repos:v1.51.0
repos:v1.50.0
repos:v1.49.0
repos:v1.48.0
repos:v1.47.2
repos:v1.47.1
repos:v1.47.0
repos:v1.46.0
repos:v1.45.0
repos:v1.44.0
repos:v1.43.0
repos:v1.42.0
repos:v1.41.0
repos:v1.40.0
repos:v1.39.0
repos:v1.38.0
repos:v1.37.0
repos:v1.36.0
repos:v1.35.0
repos:v1.34.0
repos:v1.33.0
repos:v1.32.1
repos:v1.32.0
repos:v1.31.1
repos:v1.31.0
repos:v1.30.2
repos:v1.30.1
repos:v1.30.0
repos:v1.29.1
repos:v1.29.0
repos:v1.28.0
repos:v1.27.0
repos:v1.26.4
repos:v1.26.3
repos:v1.26.2
repos:v1.26.1
repos:v1.26.0
repos:v1.25.1
repos:v1.25.0
repos:v1.24.0
repos:v1.23.0
repos:v1.22.0
repos:v1.21.0
repos:v1.20.0
repos:v1.19.0
repos:v1.18.0
repos:v1.17.0
repos:v1.16.0
repos:v1.15.0
repos:v1.14.0
repos:v1.13.0
repos:v1.12.0
repos:v1.11.0
repos:v1.10.0
repos:v1.9.0
repos:v1.8.0
repos:v1.7.0
repos:v1.6.0
repos:v1.5.0
repos:v1.4.1
repos:v1.4.0
repos:v1.3.1
repos:v1.3.0
repos:v1.2.0
repos:v1.1.0
repos:v1.0.11
repos:v1.0.10
repos:v1.0.9
repos:v1.0.8
repos:v1.0.7
repos:v1.0.6
repos:v1.0.5
repos:v1.0.4
repos:v1.0.3
repos:v1.0.2
repos:v1.0.1
repos:v1.0.0
..
compare: repos:v1.51.0
repos:v1.51.0
repos:v1.50.0
repos:v1.49.0
repos:v1.48.0
repos:v1.47.2
repos:v1.47.1
repos:v1.47.0
repos:v1.46.0
repos:v1.45.0
repos:v1.44.0
repos:v1.43.0
repos:v1.42.0
repos:v1.41.0
repos:v1.40.0
repos:v1.39.0
repos:v1.38.0
repos:v1.37.0
repos:v1.36.0
repos:v1.35.0
repos:v1.34.0
repos:v1.33.0
repos:v1.32.1
repos:v1.32.0
repos:v1.31.1
repos:v1.31.0
repos:v1.30.2
repos:v1.30.1
repos:v1.30.0
repos:v1.29.1
repos:v1.29.0
repos:v1.28.0
repos:v1.27.0
repos:v1.26.4
repos:v1.26.3
repos:v1.26.2
repos:v1.26.1
repos:v1.26.0
repos:v1.25.1
repos:v1.25.0
repos:v1.24.0
repos:v1.23.0
repos:v1.22.0
repos:v1.21.0
repos:v1.20.0
repos:v1.19.0
repos:v1.18.0
repos:v1.17.0
repos:v1.16.0
repos:v1.15.0
repos:v1.14.0
repos:v1.13.0
repos:v1.12.0
repos:v1.11.0
repos:v1.10.0
repos:v1.9.0
repos:v1.8.0
repos:v1.7.0
repos:v1.6.0
repos:v1.5.0
repos:v1.4.1
repos:v1.4.0
repos:v1.3.1
repos:v1.3.0
repos:v1.2.0
repos:v1.1.0
repos:v1.0.11
repos:v1.0.10
repos:v1.0.9
repos:v1.0.8
repos:v1.0.7
repos:v1.0.6
repos:v1.0.5
repos:v1.0.4
repos:v1.0.3
repos:v1.0.2
repos:v1.0.1
repos:v1.0.0
1 Commits
0b2cf11c6a
...
v1.51.0
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
| e4f753c9a1 |
feat(deps): Update dependency requests to v2.33.0 [SECURITY] (#436)
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [requests](https://github.com/psf/requests) ([changelog](https://github.com/psf/requests/blob/master/HISTORY.md)) | `2.32.5` → `2.33.0` |  |  |
---
### Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
[CVE-2026-25645](https://nvd.nist.gov/vuln/detail/CVE-2026-25645) / [GHSA-gc5v-m9x4-r6x2](https://github.com/advisories/GHSA-gc5v-m9x4-r6x2)
<details>
<summary>More information</summary>
#### Details
##### Impact
The `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one.
##### Affected usages
**Standard usage of the Requests library is not affected by this vulnerability.** Only applications that call `extract_zipped_paths()` directly are impacted.
##### Remediation
Upgrade to at least Requests 2.33.0, where the library now extracts files to a non-deterministic location.
If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
#### Severity
- CVSS Score: 4.4 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N`
#### References
- [https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2](https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2)
- [
|