CVE-2015-2296

requests <2.5.3 - SSRF

Title source: llm

Description

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

Scores

EPSS 0.0114
EPSS Percentile 78.1%

Classification

Status draft

Affected Products (15)

mageia_project/mageia
python/requests
python/requests
python/requests
python/requests
python/requests
python/requests
python/requests
python/requests
python/requests
python/requests
python/requests
canonical/ubuntu_linux
canonical/ubuntu_linux
pypi/requests < 2.6.0PyPI

Timeline

Published Mar 18, 2015
Tracked Since Feb 18, 2026