cbcvebase.
CVE-2024-47081
published 2025-06-09

CVE-2024-47081: Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific…

PriorityP428medium5.3CVSS 3.1
AVNACHPRNUIRSUCHINAN
EPSS
0.84%
53.8th percentile
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianrequests< requests 2.32.4+dfsg-1 (forky)requests 2.32.4+dfsg-1 (forky)
msrcazl3_python-requests_2.31.0-3_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0
msrccbl2_python-requests_2.27.1-8_on_cbl_mariner_2.0
msrccbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0
msrccm2_python-requests_2.27.1-8_on_cbl_mariner_2.0
psfrequests< 2.32.42.32.4
pythonrequests>= 0 < 2.32.3+dfsg-5+deb13u12.32.3+dfsg-5+deb13u1
pythonrequests>= 0 < 2.32.4+dfsg-12.32.4+dfsg-1
pythonrequests>= 0 < 2.32.42.32.4
pythonrequests>= 0 < 2.25.1+dfsg-2ubuntu0.32.25.1+dfsg-2ubuntu0.3
pythonrequests>= 0 < 2.31.0+dfsg-1ubuntu1.12.31.0+dfsg-1ubuntu1.1
pythonrequests>= 0 < 2.2.1-1ubuntu0.4+esm12.2.1-1ubuntu0.4+esm1
pythonrequests>= 0 < 2.9.1-3ubuntu0.1+esm22.9.1-3ubuntu0.1+esm2
pythonrequests>= 0 < 2.18.4-2ubuntu0.1+esm22.18.4-2ubuntu0.1+esm2
pythonrequests>= 0 < 2.22.0-2ubuntu1.1+esm12.22.0-2ubuntu1.1+esm1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.