PT-2024-6103 · Pypi+10 · Requests+10

Mikeassel

·

Published

2024-05-20

·

Updated

2026-06-03

·

CVE-2024-35195

CVSS v3.1

5.6

Medium

VectorAV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Requests versions prior to 2.32.0
Description The issue is related to the incorrect implementation of control flow in the Python Requests library, which can allow an attacker to access confidential data. When making requests through a Requests Session, if the first request is made with verify=False to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of verify. This behavior will continue for the lifecycle of the connection in the connection pool.
Recommendations
  • Upgrade to version 2.32.0 or later.
  • For versions prior to 2.32.0, avoid setting verify=False for the first request to a host while using a Requests Session.
  • For versions prior to 2.32.0, call close() on Session objects to clear existing connections if verify=False is used.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:0012
ALSA-2025:7049
ALSA-2025_0012
ALSA-2025_7049
AZL-42106
AZL-42127
AZL-42145
BDU:2024-07014
CESA-2025_0012
CVE-2024-35195
ECHO-8499-05D3-FB08
GHSA-9WX4-H78V-VM56
INFSA-2025_0012
INFSA-2025_7049
MGASA-2024-0210
OPENSUSE-SU-2024:13999-1
OPENSUSE-SU-2024_1857-1
OPENSUSE-SU-2024_1880-1
OPENSUSE-SU-2024_1937-1
OPENSUSE-SU-2024_1937-2
OPENSUSE-SU-2024_1938-1
RHSA-2024:3781
RHSA-2024:4522
RHSA-2024:9988
RHSA-2025:0012
RHSA-2025:1335
RHSA-2025:2399
RHSA-2025:7049
RHSA-2025_0012
RHSA-2025_7049
RLSA-2025:0012
SUSE-RU-2024:3598-1
SUSE-RU-2024:3599-1
SUSE-RU-2024:3600-1
SUSE-SU-2024:1857-1
SUSE-SU-2024:1880-1
SUSE-SU-2024:1880-2
SUSE-SU-2024:1937-1
SUSE-SU-2024:1937-2
SUSE-SU-2024:1938-1
SUSE-SU-2024:1946-1
SUSE-SU-2024:2068-1
SUSE-SU-2024:2182-1
SUSE-SU-2024_1857-1
SUSE-SU-2024_1880-1
SUSE-SU-2024_1880-2
SUSE-SU-2024_1937-1
SUSE-SU-2024_1937-2
SUSE-SU-2024_1946-1
SUSE-SU-2024_2068-1
SUSE-SU-2025:20034-1
SUSE-SU-2025:20094-1
USN-8344-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Requests
Rocky Linux
Suse
Ubuntu