Package compatibility
Requests 2.31
What Python versions does this Requests version support?
Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.
Declared Python requirement
- requires_python
- >=3.7,<3.12
- Tip version
- 2.31.0
- Source
- PyPI (requires_python / classifiers)
Python compatibility matrix
Evaluated against CompatHub Python VersionLines. Compatibility and lifecycle status are separate signals.
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Other Requests lines
Security
Advisories affecting Requests 2.31 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 6
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2024-47081PYSEC-2026-1872
Requests vulnerable to .netrc credentials leak via malicious URLs
- Affected:
- <2.32.4
- Fixed in:
- 2.32.4
- Source:
- OSV source · Advisory
- CVE-2024-35195PYSEC-2026-1873
Requests `Session` object does not verify requests after making first request with verify=False
- Affected:
- <2.32.0
- Fixed in:
- 2.32.0
- Source:
- OSV source · Advisory
- CVE-2026-25645PYSEC-2026-2275
- Affected:
- <2.33.0
- Fixed in:
- 2.33.0
- Source:
- OSV source · Advisory
- CVE-2026-25645GHSA-gc5v-m9x4-r6x2
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
- Affected:
- <2.33.0
- Fixed in:
- 2.33.0
- Source:
- OSV source · Advisory
- CVE-2024-47081GHSA-9hjg-9r4m-mvj7
Requests vulnerable to .netrc credentials leak via malicious URLs
- Affected:
- <2.32.4
- Fixed in:
- 2.32.4
- Source:
- OSV source · Advisory
- CVE-2024-35195GHSA-9wx4-h78v-vm56
Requests `Session` object does not verify requests after making first request with verify=False
- Affected:
- <2.32.0
- Fixed in:
- 2.32.0
- Source:
- OSV source · Advisory
