Back Linuxsecurity Fedora 43 python-requests Significant Patch CVE-2026
2.33.1 (2026-03-30) Bugfixes - Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. - Fixed Content-Type header parsing for malformed values. - Improved error consistency for malformed header values. 2.33.0 (2026-03-25) Announcements - \U0001f4e3 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. \U0001f4e3 Security - CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly. Improvements - Migrated to a PEP 517 build system using setuptools. Bugfixes - Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. Deprecations - Dropped support for Pyt...
* Tue Mar 31 2026 Lumir Balhar - 2.33.1-1 - Update to 2.33.1 (rhbz#2451396) * Tue Mar 10 2026 Benjamin A. Beasley - 2.32.5-5 - Package the use_chardet_on_py3 extra * Tue Mar 10 2026 Benjamin A. Beasley - 2.32.5-4 - Increase chardet upper limit to 7 * Sat Jan 17 2026 Fedora Release Engineering - 2.32.5-3 - Rebuilt for
* Tue Mar 31 2026 Lumir Balhar - 2.33.1-1 - Update to 2.33.1 (rhbz#2451396) * Tue Mar 10 2026 Benjamin A. Beasley - 2.32.5-5 - Package the use_chardet_on_py3 extra * Tue Mar 10 2026 Benjamin A. Beasley - 2.32.5-4 - Increase chardet upper limit to 7 * Sat Jan 17 2026 Fedora Release Engineering - 2.32.5-3 - Rebuilt for
[ 1 ] Bug #2467989 - python3-requests package lacks fix for CVE-2026-25645
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8ad863685a' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
