Back Linuxsecurity Fedora 43 python-pulp-glue Important Bugfix CVE-2026
2.33.1 (2026-03-30) Bugfixes - Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. - Fixed Content-Type header parsing for malformed values. - Improved error consistency for malformed header values. 2.33.0 (2026-03-25) Announcements - \U0001f4e3 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. \U0001f4e3 Security - CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly. Improvements - Migrated to a PEP 517 build system using setuptools. Bugfixes - Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. Deprecations - Dropped support for Pyt...
* Thu Apr 2 2026 Lumir Balhar - 0.37.0-5 - Remove upper version bound on requests * Tue Feb 17 2026 Simone Caronni - 0.37.0-4 - Clean up .gitignore
* Thu Apr 2 2026 Lumir Balhar - 0.37.0-5 - Remove upper version bound on requests * Tue Feb 17 2026 Simone Caronni - 0.37.0-4 - Clean up .gitignore
[ 1 ] Bug #2467989 - python3-requests package lacks fix for CVE-2026-25645
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8ad863685a' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
