Requests
Vendor:
First CVE: Oct 15, 2014 · Active for 11 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Requests over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 15, 2014
11 years ago
Most Recent CVE
Mar 25, 2026
122 days ago
CVE Severity & Scoring
Requests6 CVEs
83%
17%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (16.7%)
Network2 (33.3%)
Unknown3 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (33.3%)
High1 (16.7%)
Unknown3 (50.0%)
User Interaction
None2 (33.3%)
Unknown3 (50.0%)
Required1 (16.7%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None2 (33.3%)
Unknown3 (50.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18074HIGH The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for rem | Oct 9, 2018 | 7.5 | 28 | NO | NO |
CVE-2026-25645MEDIUM Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archive | Mar 25, 2026 | 5.5 | 24 | NO | NO |
CVE-2023-32681MEDIUM Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a produ | May 26, 2023 | 6.1 | 23 | NO | NO |
CVE-2015-2296MEDIUM The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a red | Mar 18, 2015 | 6.8 | 19 | NO | NO |
CVE-2014-1829MEDIUM Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request. | Oct 15, 2014 | 5.0 | 18 | NO | NO |
CVE-2014-1830MEDIUM Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request. | Oct 15, 2014 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Requests
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.3 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.5.2 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.5.1 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.5.0 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.4.3 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.4.2 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.4.1 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.4.0 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.3.0 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.2.1 | 1 | 6.8 | 3.4% | 0 | 0 |
| 2.1.0 | 1 | 6.8 | 3.4% | 0 | 0 |