Opened 6 months ago
Closed 6 months ago
#23040 closed enhancement (fixed)
requests-2.33.1 (Python module)
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (5)
comment:1 by , 6 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 6 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 654143d09d4e0d13e43520632ed6cb9153c3359c
SA-13.0-017 issued
comment:4 by , 6 months ago
| Resolution: | fixed |
|---|---|
| Status: | closed → reopened |
| Summary: | requests-2.33.0 (Python module) → requests-2.33.1 (Python module) |
Reopened for 2.33.1
2.33.1 (2026-03-30)
Bugfixes
Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary
files in the tmp directory. (#7305)
Fixed Content-Type header parsing for malformed values. (#7309)
Improved error consistency for malformed header values. (#7308)
comment:5 by , 6 months ago
| Resolution: | → fixed |
|---|---|
| Status: | reopened → closed |
Fixed at 5e26825a2307e077ff482445051d3d77c26846f6
This actually shouldn't have been marked as a security update in my commit message, but I was typing too fast.
Note:
See TracTickets
for help on using tickets.

Yet another security release in the past 24-48 hours.
2.33.0 (2026-03-25) Announcements 📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. 📣 Security CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non- deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly. Improvements Migrated to a PEP 517 build system using setuptools. (#7012) Bugfixes Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (#7205) Deprecations Dropped support for Python 3.9 following its end of support. (#7196) Documentation Various typo fixes and doc improvements.This one doesn't hurt as much as other updates though especially since we won't be affected by it much, if at all.