PT-2026-28069 · Pypi+1 · Requests+1

·

CVE-2026-25645

·

Published

2026-03-25

·

Updated

2026-07-22

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Requests versions prior to 2.33.0
Description The requests.utils.extract zipped paths() function uses a predictable filename when extracting files from zip archives into the system temporary directory. If a file with the same name already exists, it is reused without validation. A local attacker with write access to the temporary directory could pre-create a malicious file that would be loaded in place of the legitimate one. This impacts applications that directly call extract zipped paths(). The function requests.utils.extract zipped paths() is used by HTTPAdapter.cert verify() to load the CA bundle.
Recommendations Versions prior to 2.33.0 should be upgraded to version 2.33.0 or later. If upgrading is not possible, set the TMPDIR environment variable to a directory with restricted write access.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-80996
BDU:2026-07739
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-CR75797
CLEANSTART-2026-DD95169
CLEANSTART-2026-EM82280
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-NN42198
CLEANSTART-2026-NR60332
CLEANSTART-2026-SA70432
CLEANSTART-2026-SO50412
CLEANSTART-2026-UC45646
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CLEANSTART-2026-YC81398
CLEANSTART-2026-ZO99127
CVE-2026-25645
ECHO-74D4-CC6F-7870
GHSA-GC5V-M9X4-R6X2
OESA-2026-1791
OESA-2026-1909
OPENSUSE-SU-2026:10455-1
OPENSUSE-SU-2026:20926-1
PYSEC-2026-2275
SUSE-SU-2026:1218-1
SUSE-SU-2026:1644-1
SUSE-SU-2026:1647-1
SUSE-SU-2026:21036-1
SUSE-SU-2026:21063-1
SUSE-SU-2026:22055-1
SUSE-SU-2026:22091-1

Affected Products

Red Os
Requests