Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

requests-2.32.4-py3-none-any.whl: 1 vulnerabilities (highest severity is: 4.4)

Đang mở
#64 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
58/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
cli, security

Hướng nghiên cứu

Bắt đầu bằng cách xác định khai báo dependency trong repository sql-cli được đường dẫn quét tham chiếu đến và xác nhận requests 2.32.4 được ghim ở đâu. Xem lại chi tiết CVE-2026-25645 và cập nhật dependency trực tiếp lên bản phát hành đã sửa lỗi 2.33.0, sau đó chạy các test hiện có của dự án hoặc quét dependency để xác minh rằng phiên bản dễ bị tấn công đã không còn.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Mend: dependency security vulnerability
Vulnerable Library - requests-2.32.4-py3-none-any.whl

Python HTTP for Humans.

Library home page: https://files.pythonhosted.org/packages/7c/e4/56027c4a6b4ae70ca9de302488c5ca95ad4a39e190093d6c1a8ace08341b/requests-2.32.4-py3-none-any.whl

Path to dependency file: /tmp/ws-scm/sql-cli

Path to vulnerable library: /tmp/ws-ua_20260518195424_ZCYUWM/python_XKNQIE/202605181954251/env/lib/python3.12/site-packages/requests-2.32.4.dist-info

Found in HEAD commit: 68212e0c681da02608aa39ca6a7234d5a082124e

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (requests version) Remediation Possible**
CVE-2026-25645 Medium 4.4 requests-2.32.4-py3-none-any.whl Direct https://github.com/psf/requests.git - v2.33.0 ✅

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-25645
Vulnerable Library - requests-2.32.4-py3-none-any.whl

Python HTTP for Humans.

Library home page: https://files.pythonhosted.org/packages/7c/e4/56027c4a6b4ae70ca9de302488c5ca95ad4a39e190093d6c1a8ace08341b/requests-2.32.4-py3-none-any.whl

Path to dependency file: /tmp/ws-scm/sql-cli

Path to vulnerable library: /tmp/ws-ua_20260518195424_ZCYUWM/python_XKNQIE/202605181954251/env/lib/python3.12/site-packages/requests-2.32.4.dist-info

Dependency Hierarchy:

  • ❌ requests-2.32.4-py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 68212e0c681da02608aa39ca6a7234d5a082124e

Found in base branch: main

Vulnerability Details

Requests is a HTTP library. Prior to version 2.33.0, the "requests.utils.extract_zipped_paths()" utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call "extract_zipped_paths()" directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set "TMPDIR" in their environment to a directory with restricted write access.

Publish Date: 2026-03-25

URL: CVE-2026-25645

CVSS 3 Score Details (4.4)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: High
    • Privileges Required: Low
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-03-25

Fix Resolution: https://github.com/psf/requests.git - v2.33.0

⛑️ Automatic Remediation will be attempted for this issue.


:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.

Ngôn ngữ chính
Python
Star
9
Fork
24
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của opensearch-project/sql-cli

Tất cả issue của opensearch-project/sql-cli

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.