Insecure Temporary File in Requests - CVE-2026-25645

 

Insecure Temporary File in Requests - CVE-2026-25645

Published: July 2, 2026


Vulnerability identifier: #VU136685
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25645
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to overwrite or substitute extracted files.

The vulnerability exists due to insecure temporary file handling in requests.utils.extract_zipped_paths() when extracting files from zip archives into the system temporary directory. A local user can pre-create a malicious file to overwrite or substitute extracted files.

Only applications that call extract_zipped_paths() directly are affected. User interaction is required to process a crafted zip archive.


Affected software

Requests
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Basesystem Module
Python 3 Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Python for Scientific Computing
DataStage on Cloud Pak for Data
SOAR QRadar Plugin App
Maximo Application Suite - Monitor Component
Maximo Application Suite - Visual Inspection Component
IBM Business Automation Workflow
python-pulp-glue
requests (Ubuntu package)
python-requests
python3-requests
python2-requests
python-requests-help
python311-requests
python3-requests+socks
python3-requests+security
python-requests-doc
python313-requests
pypy
python3-pip
python-pip
python-pip-help
python-pip-wheel
QRadar Manager for YARA and SIGMA Rules App

How to mitigate CVE-2026-25645

Install security update from vendor's website.

Requests - update to 2.33.0
Python for Scientific Computing - update to 4.3.2
DataStage on Cloud Pak for Data - update to 5.3.1 patch 14
SOAR QRadar Plugin App - update to 5.6.5
Maximo Application Suite - Monitor Component - addressed in versions 9.0.22, 9.1.12
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.21, 9.1.18
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
python-pulp-glue - addressed in versions 0.37.0-5.fc43, 0.37.0-5.fc44
QRadar Manager for YARA and SIGMA Rules App - update to 2.4.1
requests (Ubuntu package) - addressed in versions 2.22.0-2ubuntu1.1+esm2, 2.25.1+dfsg-2ubuntu0.4, 2.31.0+dfsg-1ubuntu1.2, 2.32.5+dfsg-1ubuntu1.1
python-requests - update to 2.24.0-8.26.1
python3-requests - addressed in versions 2.24.0-8.26.1, 2.25.1-150300.3.21.1
python2-requests - update to 2.25.1-150300.3.21.1
python-requests-help - update to 2.31.0-5
python3-requests - update to 2.31.0-5
python-requests - update to 2.31.0-5
python311-requests - update to 2.31.0-150400.6.21.1
python3-requests+socks - update to 2.32.3-3
python3-requests+security - update to 2.32.3-3
python-requests-doc - update to 2.32.3-3
python3-requests - update to 2.32.3-3
python313-requests - update to 2.32.4-160000.3.1
python-requests - addressed in versions 2.33.1-1.fc43, 2.33.1-1.fc44
pypy - addressed in versions 7.3.21-8.fc43, 7.3.21-8.fc44, 7.3.21-8.fc45
python3-pip - update to 21.3.1-15
python-pip - update to 21.3.1-15
python-pip-help - update to 21.3.1-15
python-pip-wheel - update to 21.3.1-15

External References

Related Security Bulletins