PT-2025-54887 · Suse · Python-Requests

Published

2025-03-28

·

Updated

2025-03-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This update for python-requests fixes the following issues:
  • Add patch to inject the default CA bundles if they are not specified. (bsc#1226321, bsc#1231500)
  • Remove Requires on python-py.
  • update to 2.32.3:
  • Fixed bug breaking the ability to specify custom SSLContexts in sub-classes of HTTPAdapter.
  • Fixed issue where Requests started failing to run on Python versions compiled without the ssl module.
  • To provide a more stable migration for custom HTTPAdapters impacted by the CVE changes in 2.32.0, we've renamed get connection to a new public API, get connection with tls context. Existing custom HTTPAdapters will need to migrate their code to use this new API. get connection is
  • Fixed an issue where setting verify=False on the first request from a Session will cause subsequent requests to the same origin to also ignore cert verification,
  • verify=True now reuses a global SSLContext which should improve request time
  • Requests now supports optional use of character detection (chardet or charset normalizer) when repackaged or vendored. This enables pip and other projects to minimize their
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

SUSE-SU-2025:20255-1

Affected Products

Python-Requests