Requests vulnerable to .netrc credentials leak via malicious URLs
Description
Published by the National Vulnerability Database
Jun 9, 2025
Published to the GitHub Advisory Database
Jun 9, 2025
Reviewed
Jun 9, 2025
Last updated
Jun 9, 2025
Impact
Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.
Workarounds
For older versions of Requests, use of the .netrc file can be disabled with
trust_env=Falseon your Requests Session (docs).References
psf/requests#6965
https://seclists.org/fulldisclosure/2025/Jun/2
References