All 5 CVE vulnerabilities found in Requests, with AI-generated Chinese analysis, references, and POCs.
Vendor: WordPress
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-25645 | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function CWE-377 | 4.4 | Medium | 2026-03-25 |
| CVE-2024-47081 | Requests vulnerable to .netrc credentials leak via malicious URLs CWE-522 | 5.3 | Medium | 2025-06-09 |
| CVE-2024-35195 | Requests `Session` object does not verify requests after making first request with verify=False CWE-670 | 5.6 | Medium | 2024-05-20 |
| CVE-2023-32681 | Unintended leak of Proxy-Authorization header in requests CWE-200 | 6.1 | Medium | 2023-05-26 |
| CVE-2021-29476 | Insecure Deserialization of untrusted data in rmccue/requests CWE-502 | 9.8 | Critical | 2021-04-27 |
All 5 known CVE vulnerabilities affecting Requests with full Chinese analysis, references, and POCs where available.