Insecure Temporary File in Requests - CVE-2026-25645
Published: July 2, 2026
Vulnerability details
The vulnerability allows a local user to overwrite or substitute extracted files.
The vulnerability exists due to insecure temporary file handling in requests.utils.extract_zipped_paths() when extracting files from zip archives into the system temporary directory. A local user can pre-create a malicious file to overwrite or substitute extracted files.
Only applications that call extract_zipped_paths() directly are affected. User interaction is required to process a crafted zip archive.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Basesystem Module
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Python for Scientific Computing
python-pulp-glue
python-requests
python3-requests
python2-requests
python-requests-help
python311-requests
python3-requests+socks
python3-requests+security
python-requests-doc
python313-requests
pypy
python3-pip
python-pip-wheel
python-pip-help
python-pip
How to mitigate CVE-2026-25645
Python for Scientific Computing - update to 4.3.2
python-pulp-glue - addressed in versions 0.37.0-5.fc43, 0.37.0-5.fc44
python-requests - update to 2.24.0-8.26.1
python3-requests - addressed in versions 2.24.0-8.26.1, 2.25.1-150300.3.21.1
python2-requests - update to 2.25.1-150300.3.21.1
python-requests - update to 2.31.0-5
python-requests-help - update to 2.31.0-5
python3-requests - update to 2.31.0-5
python311-requests - update to 2.31.0-150400.6.21.1
python3-requests - update to 2.32.3-3
python3-requests+socks - update to 2.32.3-3
python3-requests+security - update to 2.32.3-3
python-requests-doc - update to 2.32.3-3
python313-requests - update to 2.32.4-160000.3.1
python-requests - addressed in versions 2.33.1-1.fc43, 2.33.1-1.fc44
pypy - addressed in versions 7.3.21-8.fc43, 7.3.21-8.fc44, 7.3.21-8.fc45
python3-pip - update to 21.3.1-15
python-pip-wheel - update to 21.3.1-15
python-pip-help - update to 21.3.1-15
python-pip - update to 21.3.1-15
External References
Related Security Bulletins
- Insecure temporary file handling in Python Requests library
- Splunk Python for Scientific Computing update for third-party components
- Fedora 45 update for pypy
- Fedora 44 update for pypy
- Fedora 43 update for pypy
- Fedora 44 update for python-pulp-glue, python-requests
- Fedora 43 update for python-pulp-glue, python-requests
- openEuler update for python-requests
- openEuler update for python-pip
- SUSE update for python-requests
- SUSE update for python-requests
- SUSE update for python-requests
- SUSE update for python-requests
- Anolis OS update for python-requests