CVE-2024-35195

MEDIUM

Requests <2.32.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.

Scores

CVSS v3 5.6
EPSS 0.0005
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-670
Status published
Products (2)
psf/requests < 2.32.0
pypi/requests 0 - 2.32.0PyPI
Published May 20, 2024
Tracked Since Feb 18, 2026