CVE-2026-25645
published 2026-03-25CVE-2026-25645: Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting…
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.18%
8.0th percentile
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | requests | — | — |
| msrc | azl3_python-requests_2.31.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python-requests_2.27.1-8_on_cbl_mariner_2.0 | — | — |
| psf | requests | < 2.33.0 | 2.33.0 |
| python | requests | < 2.33.0 | 2.33.0 |
| python | requests | >= 0 < 2.33.0 | 2.33.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-25645: (Requests is a HTTP library
osv·2026-04-06·CVSS 5.5
CVE-2026-25645 [MEDIUM] CVE-2026-25645: (Requests is a HTTP library
(Requests is a HTTP library. Prior to version 2.33.0, the `requests.uti ...)
OSV
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
osv·2026-04-01·CVSS 5.5
CVE-2026-25645 [MEDIUM] poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
Pin vulnerable version of requests library
GHSA
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
ghsa·2026-04-01·CVSS 5.5
CVE-2026-25645 [MEDIUM] CWE-377 poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
Pin vulnerable version of requests library
OSV
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
osv·2026-03-25
CVE-2026-25645 [MEDIUM] Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
### Impact
The `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one.
### Affected usages
**Standard usage of the Requests library is not affected by this vulnerability.** Only applications that call `extract_zipped_paths()` directly are impacted.
### Remediation
Upgrade to at least Requests 2.33.0, where the library now extracts files to a non-deterministic location.
If developers are una
GHSA
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
ghsa·2026-03-25
CVE-2026-25645 [MEDIUM] CWE-377 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
### Impact
The `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one.
### Affected usages
**Standard usage of the Requests library is not affected by this vulnerability.** Only applications that call `extract_zipped_paths()` directly are impacted.
### Remediation
Upgrade to at least Requests 2.33.0, where the library now extracts files to a non-deterministic location.
If developers are una
OSV
CVE-2026-25645: Requests is a HTTP library
osv·2026-03-25·CVSS 5.5
CVE-2026-25645 [MEDIUM] CVE-2026-25645: Requests is a HTTP library
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
Red Hat
requests: Requests: Security bypass due to predictable temporary file creation
vendor_redhat·2026-03-25·CVSS 4.4
CVE-2026-25645 [MEDIUM] CWE-379 requests: Requests: Security bypass due to predictable temporary file creation
requests: Requests: Security bypass due to predictable temporary file creation
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can s
Microsoft
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
vendor_msrc·2026-03-10·CVSS 4.4
CVE-2026-25645 [MEDIUM] CWE-377 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Debian
CVE-2026-25645: requests - Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract...
vendor_debian·2026·CVSS 4.4
CVE-2026-25645 [MEDIUM] CVE-2026-25645: requests - Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract...
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
Sc
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-25645 python-pip: Requests: Security bypass due to predictable temporary file creation [fedora-all]
bugzilla·2026-03-27·CVSS 5.5
CVE-2026-25645 [MEDIUM] CVE-2026-25645 python-pip: Requests: Security bypass due to predictable temporary file creation [fedora-all]
CVE-2026-25645 python-pip: Requests: Security bypass due to predictable temporary file creation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This is 4.7 CVSS v3 Score. We will likely update pip in rawhide and let it remain unfixed in older Fedoras.
Bugzilla
CVE-2026-25645 python-botocore: Requests: Security bypass due to predictable temporary file creation [fedora-all]
bugzilla·2026-03-27·CVSS 5.5
CVE-2026-25645 [MEDIUM] CVE-2026-25645 python-botocore: Requests: Security bypass due to predictable temporary file creation [fedora-all]
CVE-2026-25645 python-botocore: Requests: Security bypass due to predictable temporary file creation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2026-25645 python3.15: Requests: Security bypass due to predictable temporary file creation [fedora-all]
bugzilla·2026-03-27·CVSS 4.4
CVE-2026-25645 [MEDIUM] CVE-2026-25645 python3.15: Requests: Security bypass due to predictable temporary file creation [fedora-all]
CVE-2026-25645 python3.15: Requests: Security bypass due to predictable temporary file creation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The vulnerable function is not called from pip bundled in Python.
Bugzilla
CVE-2026-25645 python3.6: Requests: Security bypass due to predictable temporary file creation [fedora-all]
bugzilla·2026-03-27·CVSS 4.4
CVE-2026-25645 [MEDIUM] CVE-2026-25645 python3.6: Requests: Security bypass due to predictable temporary file creation [fedora-all]
CVE-2026-25645 python3.6: Requests: Security bypass due to predictable temporary file creation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
pip indeed bundles requests, and Python bundles pip, but the vulnerable function `extract_zipped_paths` is not used anywhere in pip's source code.
Bugzilla
CVE-2026-25645 pypy: Requests: Security bypass due to predictable temporary file creation [fedora-all]
bugzilla·2026-03-27·CVSS 4.4
CVE-2026-25645 [MEDIUM] CVE-2026-25645 pypy: Requests: Security bypass due to predictable temporary file creation [fedora-all]
CVE-2026-25645 pypy: Requests: Security bypass due to predictable temporary file creation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creation
bugzilla·2026-03-25·CVSS 5.5
CVE-2026-25645 [MEDIUM] CVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creation
CVE-2026-25645 requests: Requests: Security bypass due to predictable temporary file creation
Requests is a HTTP library. Prior to version 2.33.0, the function `requests.utils.extract_zipped_paths()` (which is used by `HTTPAdapter.cert_verify()` to load the CA bundle, often from the `certifi` package's zipapp structure) uses a predictable, non-unique filename (the basename of the file, e.g., `cacert.pem`) when attempting to extract files into the system's temporary directory (`/tmp`). The vulnerable logic performs a check to see if the target file already exists in `/tmp` and re-uses the existing file if found, instead of securely checking the file's content or ensuring atomic, unique extraction. This allows a Local Attacker to pre-create a malicious CA bundle file (e.g., `/tmp/cacert.pem
Wiz
CVE-2026-25645 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-25645 [MEDIUM] CVE-2026-25645 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25645 :
Python vulnerability analysis and mitigation
requests.utils.extract_zipped_paths()
extract_zipped_paths()
TMPDIR
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
Python
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
checkov
python3.12-pip-wheel
Sources
NVD
Chainguard Has Fix Added at: Mar 26, 2026
Debian 11, 12, 13, 14 Severity MEDIUM No Fix Added at: Mar 29, 2026
Echo Severity MEDIUM No Fix Added at: Mar 29, 2026
pip Severity MEDIUM Has Fix Added at: Mar 26, 2026
MinimOS Severity MEDIUM Has Fix Added at: Apr 05, 2026
Re
2026-03-25
Published