VDB
Sign up
MEDIUM5.3

PYSEC-2026-1872

Requests vulnerable to .netrc credentials leak via malicious URLs

Quick fix

PYSEC-2026-1872 — requests: upgrade to the fixed version with the command below.

pip install --upgrade 'requests>=2.32.4'

Details

### Impact

Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.

### Workarounds For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on your Requests Session ([docs](https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env)).

### References https://github.com/psf/requests/pull/6965 https://seclists.org/fulldisclosure/2025/Jun/2

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/requests
Introduced in: 0Fixed in: 2.32.4
Fixpip install --upgrade 'requests>=2.32.4'

References