INFSA-2023:4520: python-requests security update

Information about definition

Identificator: INFSA-2023:4520

Type: security

Release date: 2025-10-31 13:21:59 UTC

Information about package

The python-requests package contains a library designed to make HTTP requests easy for developers.

Vulnerabilities description

  • CVE-2023-32681

    A flaw was found in the Python-requests package, where it is vulnerable to potentially leaking Proxy-Authorization headers to destination servers, specifically during redirects to an HTTPS origin. This is a product of how rebuild_proxies is used to recompute and reattach the Proxy-Authorization header to requests when redirected. This behavior only affects proxied requests when credentials are supplied in the URL user information component (for example, https://username:password@proxy:8080).

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 6.1 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download