Known Vulnerabilities for Requests by Python-requests
Listed below are 1 of the newest known vulnerabilities associated with "Requests" by "Python-requests".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78003 json | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in vers... | Not Provided | 2026-08-22 | 2026-08-22 |
| CVE-2026-77220 json | PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a point... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77087 json | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary ... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77085 json | n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent reques... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-77074 json | n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-77069 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-acc... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-77067 json | The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address val... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-77066 json | The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.g... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-76905 json | kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openap... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76850 json | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disa... | Not Provided | 2026-08-19 | 2026-08-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python-requests | Requests | 2.9.2 | |||
| Application | Python-requests | Requests | 2.9.1 | |||
| Application | Python-requests | Requests | 2.9.0 | |||
| Application | Python-requests | Requests | 2.8.1 | |||
| Application | Python-requests | Requests | 2.8.0 | |||
| Application | Python-requests | Requests | 2.7.0 | |||
| Application | Python-requests | Requests | 2.6.2 | |||
| Application | Python-requests | Requests | 2.6.1 | |||
| Application | Python-requests | Requests | 2.6.0 | |||
| Application | Python-requests | Requests | 2.5.3 | |||
| Application | Python-requests | Requests | 2.5.2 | |||
| Application | Python-requests | Requests | 2.5.1 | |||
| Application | Python-requests | Requests | 2.5.0 | |||
| Application | Python-requests | Requests | 2.4.3 | |||
| Application | Python-requests | Requests | 2.4.2 | |||
| Application | Python-requests | Requests | 2.4.1 | |||
| Application | Python-requests | Requests | 2.4.0 | |||
| Application | Python-requests | Requests | 2.3.0 | |||
| Application | Python-requests | Requests | 2.22.0 | |||
| Application | Python-requests | Requests | 2.21.0 |