CVE-2024-47081

NameCVE-2024-47081
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1107368

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
requests (PTS)bullseye2.25.1+dfsg-2vulnerable
bookworm2.28.1+dfsg-1vulnerable
trixie, sid2.32.3+dfsg-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
requestssource(unstable)(unfixed)1107368

Notes

[bookworm] - requests <postponed> (Minor issue; revisit when fixed upstream)
[bullseye] - requests <postponed> (Minor issue; revisit when fixed upstream)
https://www.openwall.com/lists/oss-security/2025/06/03/9
https://github.com/psf/requests/pull/6965
Fixed by: https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef
Testcase: https://github.com/psf/requests/commit/7bc45877a86192af77645e156eb3744f95b47dae

Search for package or bug name: Reporting problems