Insecure Temporary File in Requests - CVE-2026-25645
Published: July 2, 2026
Vulnerability details
The vulnerability allows a local user to overwrite or substitute extracted files.
The vulnerability exists due to insecure temporary file handling in requests.utils.extract_zipped_paths() when extracting files from zip archives into the system temporary directory. A local user can pre-create a malicious file to overwrite or substitute extracted files.
Only applications that call extract_zipped_paths() directly are affected. User interaction is required to process a crafted zip archive.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Basesystem Module
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Python for Scientific Computing
DataStage on Cloud Pak for Data
SOAR QRadar Plugin App
Maximo Application Suite - Monitor Component
Maximo Application Suite - Visual Inspection Component
IBM Business Automation Workflow
python-pulp-glue
requests (Ubuntu package)
python-requests
python3-requests
python2-requests
python-requests-help
python311-requests
python3-requests+socks
python3-requests+security
python-requests-doc
python313-requests
pypy
python3-pip
python-pip
python-pip-help
python-pip-wheel
QRadar Manager for YARA and SIGMA Rules App
How to mitigate CVE-2026-25645
Python for Scientific Computing - update to 4.3.2
DataStage on Cloud Pak for Data - update to 5.3.1 patch 14
SOAR QRadar Plugin App - update to 5.6.5
Maximo Application Suite - Monitor Component - addressed in versions 9.0.22, 9.1.12
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.21, 9.1.18
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
python-pulp-glue - addressed in versions 0.37.0-5.fc43, 0.37.0-5.fc44
QRadar Manager for YARA and SIGMA Rules App - update to 2.4.1
requests (Ubuntu package) - addressed in versions 2.22.0-2ubuntu1.1+esm2, 2.25.1+dfsg-2ubuntu0.4, 2.31.0+dfsg-1ubuntu1.2, 2.32.5+dfsg-1ubuntu1.1
python-requests - update to 2.24.0-8.26.1
python3-requests - addressed in versions 2.24.0-8.26.1, 2.25.1-150300.3.21.1
python2-requests - update to 2.25.1-150300.3.21.1
python-requests-help - update to 2.31.0-5
python3-requests - update to 2.31.0-5
python-requests - update to 2.31.0-5
python311-requests - update to 2.31.0-150400.6.21.1
python3-requests+socks - update to 2.32.3-3
python3-requests+security - update to 2.32.3-3
python-requests-doc - update to 2.32.3-3
python3-requests - update to 2.32.3-3
python313-requests - update to 2.32.4-160000.3.1
python-requests - addressed in versions 2.33.1-1.fc43, 2.33.1-1.fc44
pypy - addressed in versions 7.3.21-8.fc43, 7.3.21-8.fc44, 7.3.21-8.fc45
python3-pip - update to 21.3.1-15
python-pip - update to 21.3.1-15
python-pip-help - update to 21.3.1-15
python-pip-wheel - update to 21.3.1-15
External References
Related Security Bulletins
- Insecure temporary file handling in Python Requests library
- Splunk Python for Scientific Computing update for third-party components
- Fedora 45 update for pypy
- Fedora 44 update for pypy
- Fedora 43 update for pypy
- Fedora 44 update for python-pulp-glue, python-requests
- Fedora 43 update for python-pulp-glue, python-requests
- openEuler update for python-requests
- openEuler update for python-pip
- SUSE update for python-requests
- SUSE update for python-requests
- SUSE update for python-requests
- SUSE update for python-requests
- Anolis OS update for python-requests
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- IBM Maximo Application Suite - Visual Inspection Component update for Requests
- IBM SOAR QRadar Plugin App update for Requests
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in The Manager for YARA and SIGMA App for IBM QRadar SIEM
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Ubuntu update for requests