MEDIUM5.3
PYSEC-2026-1872
Requests vulnerable to .netrc credentials leak via malicious URLs
Quick fix
PYSEC-2026-1872 — requests: upgrade to the fixed version with the command below.
pip install --upgrade 'requests>=2.32.4'Details
### Impact
Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.
### Workarounds For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on your Requests Session ([docs](https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env)).
### References https://github.com/psf/requests/pull/6965 https://seclists.org/fulldisclosure/2025/Jun/2
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-47081[ADVISORY]
- https://github.com/psf/requests/pull/6965[WEB]
- https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef[FIX]
- https://github.com/psf/requests[PACKAGE]
- https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env[WEB]
- https://seclists.org/fulldisclosure/2025/Jun/2[WEB]
- http://seclists.org/fulldisclosure/2025/Jun/2[WEB]
- http://www.openwall.com/lists/oss-security/2025/06/03/11[WEB]
- http://www.openwall.com/lists/oss-security/2025/06/03/9[WEB]
- http://www.openwall.com/lists/oss-security/2025/06/04/1[WEB]
- http://www.openwall.com/lists/oss-security/2025/06/04/6[WEB]
- https://pypi.org/project/requests[PACKAGE]
- https://github.com/advisories/GHSA-9hjg-9r4m-mvj7[ADVISORY]