Debian Package Tracker
Register | Log in
Subscribe

requests

Choose email to subscribe with

general
  • source: requests (main)
  • version: 2.34.2-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Daniele Tricoli [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.25.1+dfsg-2
  • oldstable: 2.28.1+dfsg-1
  • stable: 2.32.3+dfsg-5+deb13u1
  • testing: 2.32.5+dfsg-2
  • unstable: 2.34.2-1
versioned links
  • 2.25.1+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.28.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.32.3+dfsg-5+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.32.5+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.34.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-requests-doc
  • python3-requests (2 bugs: 0, 2, 0, 0)
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-25645: Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
Created: 2026-03-26 Last update: 2026-08-02 20:32
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-07-05 Last update: 2026-08-06 11:01
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-25645: (needs triaging) Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-03-26 Last update: 2026-08-02 20:32
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 2.34.2-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-30 19:02
testing migrations
  • excuses:
    • Migration status for requests (2.32.5+dfsg-2 to 2.34.2-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for azure-cli/2.88.0-1: amd64: Pass ♻, arm64: Pass ♻ (reference ♻), armhf: Pass ♻ (reference ♻), i386: Pass ♻, loong64: Pass ♻ (reference ♻), ppc64el: Pass ♻ (reference ♻), riscv64: Pass ♻ (reference ♻), s390x: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for beets/2.12.0-1: loong64: Pass ♻, riscv64: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for debusine/0.15.0: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Pass, loong64: Pass, ppc64el: Pass, riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for dolfin/2019.2.0~legacy20240219.1c52e83-30: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for fenics-dolfinx/1:0.10.0.post5-8: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Pass, loong64: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for horizon/3:25.7.3-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for jellyfin-apiclient-python/1.17.0-1: loong64: Pass ♻, riscv64: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for llama.cpp/10108+dfsg1-2: loong64: Pass ♻ (reference ♻), riscv64: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for python-alpha-vantage/3.0.0-1: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for python-dropbox/12.0.2-2: amd64: No tests, superficial or marked flaky ♻ (reference ♻), arm64: No tests, superficial or marked flaky ♻ (reference ♻), armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻, loong64: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for python-elevenlabs/2.54.0-1: loong64: Pass ♻, ppc64el: Pass ♻ (reference ♻), riscv64: Pass ♻, s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-openapi-core/0.23.1-3: loong64: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for python-requests-cache/1.3.1-1: amd64: Regression ♻ (reference ♻), arm64: Regression ♻ (reference ♻), armhf: Regression ♻ (reference ♻), i386: Regression ♻ (reference ♻), loong64: Regression ♻ (reference ♻), ppc64el: Regression ♻ (reference ♻), riscv64: Regression ♻ (reference ♻), s390x: Regression ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for python-treq/25.5.0-2: loong64: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for requests/2.34.2-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, loong64: Pass, ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Autopkgtest for requests-ratelimiter/0.10.0-1: amd64: Regression ♻ (reference ♻), arm64: Regression ♻ (reference ♻), armhf: Regression ♻ (reference ♻), i386: Regression ♻ (reference ♻), loong64: Regression ♻ (reference ♻), ppc64el: Regression ♻ (reference ♻), riscv64: Regression ♻ (reference ♻), s390x: Regression ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for streamlink/8.4.0-2: amd64: Regression ♻ (reference ♻), arm64: Regression ♻ (reference ♻), armhf: Regression ♻ (reference ♻), i386: Regression ♻ (reference ♻), loong64: Regression ♻ (reference ♻), ppc64el: Regression ♻ (reference ♻), riscv64: Regression ♻ (reference ♻), s390x: Regression ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for swift/2.37.1-6: amd64: Ignored failure ♻ (reference ♻), arm64: Pass, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻, loong64: No tests, superficial or marked flaky ♻ (reference ♻), ppc64el: Ignored failure ♻ (reference ♻), riscv64: Ignored failure ♻ (reference ♻), s390x: Test triggered (failure will be ignored)
    • Additional info (not blocking):
    • ∙ ∙ Updating requests will fix bugs in testing: #1143166
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/requests.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 37 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-06-30] Accepted requests 2.34.2-1 (source) into unstable (Carsten Schoenert)
  • [2026-06-30] requests 2.32.5+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-25] Accepted requests 2.32.5+dfsg-2 (source) into unstable (Alexandre Detiste)
  • [2026-03-08] Accepted requests 2.32.3+dfsg-5+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-09-13] requests 2.32.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-29] Accepted requests 2.32.5+dfsg-1 (source) into unstable (Colin Watson)
  • [2025-08-23] requests 2.32.4+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-18] Accepted requests 2.32.4+dfsg-1 (source) into unstable (Colin Watson)
  • [2025-04-17] requests 2.32.3+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2025-03-24] Accepted requests 2.32.3+dfsg-5 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-02-23] requests 2.32.3+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2025-02-17] Accepted requests 2.32.3+dfsg-4 (source) into unstable (Colin Watson)
  • [2025-02-17] Accepted requests 2.32.3+dfsg-3 (source) into experimental (Colin Watson)
  • [2024-11-24] Accepted requests 2.32.3+dfsg-2 (source) into experimental (Alexandre Detiste)
  • [2024-08-31] requests 2.32.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-13] Accepted requests 2.32.3+dfsg-1 (source) into unstable (Colin Watson)
  • [2024-05-19] requests 2.31.0+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-05-16] Accepted requests 2.31.0+dfsg-2 (source) into unstable (Timo Röhling)
  • [2023-07-22] requests 2.31.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-17] Accepted requests 2.31.0+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2023-06-18] Accepted requests 2.21.0-1+deb10u1 (source) into oldoldstable (Markus Koschany)
  • [2022-11-26] requests 2.28.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-24] Accepted requests 2.28.1+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2022-03-31] requests 2.27.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-20] Accepted requests 2.27.1+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2021-01-06] requests 2.25.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2020-12-31] Accepted requests 2.25.1+dfsg-2 (source) into unstable (Daniele Tricoli)
  • [2020-12-31] Accepted requests 2.25.1+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2020-12-30] Accepted requests 2.25.0+dfsg-2 (source) into unstable (Daniele Tricoli)
  • [2020-12-08] Accepted requests 2.25.0+dfsg-1 (source) into unstable (Daniele Tricoli)
  • 1
  • 2
bugs [bug history graph]
  • all: 8
  • RC: 0
  • I&N: 6
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.32.5+dfsg-1ubuntu1
  • patches for 2.32.5+dfsg-1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing