Package compatibility

Requests

Python requirements from PyPI (requires_python / classifiers) for the requests package. This is not a lifecycle software page.

Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.

Version lines

Each line reflects a declared requires_python tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2024-47081PYSEC-2026-1872

    Requests vulnerable to .netrc credentials leak via malicious URLs

    Affected:
    <2.32.4
    Fixed in:
    2.32.4
    Source:
    OSV source · Advisory
  • CVE-2024-35195PYSEC-2026-1873

    Requests `Session` object does not verify requests after making first request with verify=False

    Affected:
    <2.32.0
    Fixed in:
    2.32.0
    Source:
    OSV source · Advisory
  • CVE-2026-25645PYSEC-2026-2275
    Affected:
    <2.33.0
    Fixed in:
    2.33.0
    Source:
    OSV source · Advisory
  • CVE-2026-25645GHSA-gc5v-m9x4-r6x2

    Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

    Affected:
    <2.33.0
    Fixed in:
    2.33.0
    Source:
    OSV source · Advisory
  • CVE-2024-47081GHSA-9hjg-9r4m-mvj7

    Requests vulnerable to .netrc credentials leak via malicious URLs

    Affected:
    <2.32.4
    Fixed in:
    2.32.4
    Source:
    OSV source · Advisory
  • CVE-2024-35195GHSA-9wx4-h78v-vm56

    Requests `Session` object does not verify requests after making first request with verify=False

    Affected:
    <2.32.0
    Fixed in:
    2.32.0
    Source:
    OSV source · Advisory
  • CVE-2023-32681PYSEC-2023-74
    Affected:
    <74ea7cf7a6a27a4eeb2ae24e162bcc942a6706d5; >=2.3.0,<2.31.0
    Fixed in:
    74ea7cf7a6a27a4eeb2ae24e162bcc942a6706d5, 2.31.0
    Source:
    OSV source · Advisory
  • CVE-2023-32681GHSA-j8r2-6x86-q33q

    Unintended leak of Proxy-Authorization header in requests

    Affected:
    >=2.3.0,<2.31.0
    Fixed in:
    2.31.0
    Source:
    OSV source · Advisory
  • CVE-2014-1829GHSA-cfj3-7x9c-4p3h

    Exposure of Sensitive Information to an Unauthorized Actor in Requests

    Affected:
    <2.3.0
    Fixed in:
    2.3.0
    Source:
    OSV source · Advisory
  • CVE-2014-1830GHSA-652x-xj99-gmcc

    Exposure of Sensitive Information to an Unauthorized Actor in Requests

    Affected:
    <2.3.0
    Fixed in:
    2.3.0
    Source:
    OSV source · Advisory
  • CVE-2015-2296GHSA-pg2w-x9wp-vw92

    Python Requests Session Fixation

    Affected:
    >=2.1.0,<2.6.0
    Fixed in:
    2.6.0
    Source:
    OSV source · Advisory
  • CVE-2018-18074GHSA-x84v-xcm2-53pg

    Insufficiently Protected Credentials in Requests

    Affected:
    <2.20.0
    Fixed in:
    2.20.0
    Source:
    OSV source · Advisory