Opened 6 months ago

Closed 6 months ago

#23040 closed enhancement (fixed)

requests-2.33.1 (Python module)

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (5)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → elevated

Yet another security release in the past 24-48 hours.

2.33.0 (2026-03-25)

Announcements

    📣 Requests is adding inline types. If you have a typed code base that uses 
Requests, please take a look at #7271. Give it a try, and report any gaps or feedback 
you may have in the issue. 📣

Security

    CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-
deterministic location to prevent malicious file replacement. This does not affect 
default usage of Requests, only applications calling the utility function directly.

Improvements

    Migrated to a PEP 517 build system using setuptools. (#7012)

Bugfixes

    Fixed an issue where an empty netrc entry could cause malformed authentication to be 
applied to Requests on Python 3.11+. (#7205)

Deprecations

    Dropped support for Python 3.9 following its end of support. (#7196)

Documentation

    Various typo fixes and doc improvements.

This one doesn't hurt as much as other updates though especially since we won't be affected by it much, if at all.

comment:2 by Douglas R. Reno, 6 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:3 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 654143d09d4e0d13e43520632ed6cb9153c3359c

SA-13.0-017 issued

comment:4 by Douglas R. Reno, 6 months ago

Resolution: fixed
Status: closed → reopened
Summary: requests-2.33.0 (Python module) → requests-2.33.1 (Python module)

Reopened for 2.33.1

2.33.1 (2026-03-30)

Bugfixes

    Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary
    files in the tmp directory. (#7305)
    Fixed Content-Type header parsing for malformed values. (#7309)
    Improved error consistency for malformed header values. (#7308)

comment:5 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: reopened → closed

Fixed at 5e26825a2307e077ff482445051d3d77c26846f6

This actually shouldn't have been marked as a security update in my commit message, but I was typing too fast.

Note: See TracTickets for help on using tickets.