Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-63812.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-63812
Upstream
Published
2025-06-09T18:15:24Z
Modified
2026-04-01T05:20:13.701457Z
Summary
CVE-2024-47081 affecting package python-requests for versions less than 2.27.1-8
Details

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on one's Requests Session.

References

Affected packages

Azure Linux:2 / python-requests

Package

Name
python-requests
Purl
pkg:rpm/azure-linux/python-requests

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.27.1-8

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-63812.json"