Insecure Temporary File in Requests - CVE-2026-25645

 

Insecure Temporary File in Requests - CVE-2026-25645

Published: July 2, 2026


Vulnerability identifier: #VU136685
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25645
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to overwrite or substitute extracted files.

The vulnerability exists due to insecure temporary file handling in requests.utils.extract_zipped_paths() when extracting files from zip archives into the system temporary directory. A local user can pre-create a malicious file to overwrite or substitute extracted files.

Only applications that call extract_zipped_paths() directly are affected. User interaction is required to process a crafted zip archive.


Affected software

Requests
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
SUSE Linux Micro
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Basesystem Module
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Python for Scientific Computing
python-pulp-glue
python-requests
python3-requests
python2-requests
python-requests-help
python311-requests
python3-requests+socks
python3-requests+security
python-requests-doc
python313-requests
pypy
python3-pip
python-pip-wheel
python-pip-help
python-pip

How to mitigate CVE-2026-25645

Install security update from vendor's website.

Requests - update to 2.33.0
Python for Scientific Computing - update to 4.3.2
python-pulp-glue - addressed in versions 0.37.0-5.fc43, 0.37.0-5.fc44
python-requests - update to 2.24.0-8.26.1
python3-requests - addressed in versions 2.24.0-8.26.1, 2.25.1-150300.3.21.1
python2-requests - update to 2.25.1-150300.3.21.1
python-requests - update to 2.31.0-5
python-requests-help - update to 2.31.0-5
python3-requests - update to 2.31.0-5
python311-requests - update to 2.31.0-150400.6.21.1
python3-requests - update to 2.32.3-3
python3-requests+socks - update to 2.32.3-3
python3-requests+security - update to 2.32.3-3
python-requests-doc - update to 2.32.3-3
python313-requests - update to 2.32.4-160000.3.1
python-requests - addressed in versions 2.33.1-1.fc43, 2.33.1-1.fc44
pypy - addressed in versions 7.3.21-8.fc43, 7.3.21-8.fc44, 7.3.21-8.fc45
python3-pip - update to 21.3.1-15
python-pip-wheel - update to 21.3.1-15
python-pip-help - update to 21.3.1-15
python-pip - update to 21.3.1-15

External References

Related Security Bulletins