Debian Package Tracker
Register | Log in
Subscribe

requests

Choose email to subscribe with

general
  • source: requests (main)
  • version: 2.34.2-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Daniele Tricoli [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.25.1+dfsg-2
  • oldstable: 2.28.1+dfsg-1
  • stable: 2.32.3+dfsg-5+deb13u1
  • testing: 2.32.5+dfsg-2
  • unstable: 2.34.2-1
versioned links
  • 2.25.1+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.28.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.32.3+dfsg-5+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.32.5+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.34.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-requests-doc
  • python3-requests (2 bugs: 0, 2, 0, 0)
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-25645: Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
Created: 2026-03-26 Last update: 2026-08-02 20:32
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 5-day delay is over. Check why.
Created: 2026-07-05 Last update: 2026-08-28 01:31
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-25645: (needs triaging) Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-03-26 Last update: 2026-08-02 20:32
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 2.34.2-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-30 19:02
testing migrations
  • excuses:
    • Migration status for requests (2.32.5+dfsg-2 to 2.34.2-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for apprise/1.11.0-1: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for debootstrap/1.0.144: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Regression ♻ (reference ♻), s390x: Pass
    • ∙ ∙ Autopkgtest for debusine/0.15.0: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Pass, ppc64el: Pass, riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for dolfin/2019.2.0~legacy20240219.1c52e83-30: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Pass, ppc64el: Pass, riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for eodag/4.6.0+ds-1: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for fenics-dolfinx/1:0.10.0.post5-8: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored), s390x: Pass
    • ∙ ∙ Autopkgtest for metaphlan/4.0.4+ds-1: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Failed (not a regression) ♻ (reference ♻), ppc64el: Pass, riscv64: Test triggered, s390x: Failed (not a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for nocturne/1.3.1-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for octavia/18.0.0-2: s390x: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for onionprobe/1.4.1+ds-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for onionshare/2.6.4-1: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, ppc64el: Test triggered, riscv64: Pass, s390x: Pass
    • ∙ ∙ Autopkgtest for orange3/3.40.0-4: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for osmnx/2.0.3+ds-3: i386: Pass ♻, s390x: Failed (not a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for pyatmo/9.8.0-1: arm64: Pass ♻ (reference ♻), i386: Pass ♻, riscv64: Pass ♻ (reference ♻), s390x: Pass ♻
    • ∙ ∙ Autopkgtest for pymatgen/2026.3.23+dfsg1-3: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for pypuppetdb/3.2.0-1: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-aiocentriconnect/0.2.3-1: amd64: Pass ♻ (reference ♻), arm64: Pass ♻ (reference ♻), armhf: Pass ♻ (reference ♻), i386: Pass ♻ (reference ♻), ppc64el: Pass ♻ (reference ♻), riscv64: Pass ♻ (reference ♻), s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-aiorecollect/2023.12.0-2: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-aioridwell/2024.1.0-2: s390x: Pass ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for python-designateclient/6.4.0-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Test triggered, s390x: Pass
    • ∙ ∙ Autopkgtest for python-moto/5.1.18-4: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-parsl/2026.07.27+ds-1: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-pdunehd/1.3.3-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for python-proton-core/0.7.0-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Test triggered, s390x: Pass
    • ∙ ∙ Autopkgtest for python-semantic-release/10.6.1-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for python-trezor/0.13.10-3: s390x: Pass ♻
    • ∙ ∙ Autopkgtest for python-virustotal-api/1.1.11-3: s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for requests/2.34.2-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Autopkgtest for sabnzbdplus/5.0.4+dfsg-1: s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for snakemake/7.32.4-12: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for social-auth-core/5.0.2-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for swift/2.37.1-6: amd64: Pass, arm64: Pass, armhf: No tests, superficial or marked flaky ♻ (reference ♻), i386: No tests, superficial or marked flaky ♻, ppc64el: Ignored failure ♻ (reference ♻), riscv64: Ignored failure ♻ (reference ♻), s390x: Test triggered (failure will be ignored)
    • ∙ ∙ Autopkgtest for synadm/0.49.2-2: amd64: Pass, arm64: Test triggered, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for tryton-modules-currency-ro/7.0.1-1: amd64: Failed (not a regression) ♻ (reference ♻), arm64: Failed (not a regression) ♻ (reference ♻), armhf: Failed (not a regression) ♻ (reference ♻), i386: Failed (not a regression) ♻ (reference ♻), ppc64el: Failed (not a regression) ♻ (reference ♻), riscv64: Failed (not a regression) ♻ (reference ♻), s390x: Reference test triggered, but real test failed already ♻
    • ∙ ∙ Autopkgtest for uwsgi/2.0.31-6: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for vcr.py/8.3.0-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Autopkgtest for yt-dlp/2026.07.04-1: amd64: Pass ♻ (reference ♻), arm64: Pass ♻ (reference ♻), i386: Pass ♻ (reference ♻), ppc64el: Pass ♻ (reference ♻), riscv64: Failed (not a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for zarr/3.2.1-1: s390x: Pass ♻ (reference ♻)
    • Additional info (not blocking):
    • ∙ ∙ Updating requests will fix bugs in testing: #1143166
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/requests.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 59 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-06-30] Accepted requests 2.34.2-1 (source) into unstable (Carsten Schoenert)
  • [2026-06-30] requests 2.32.5+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-25] Accepted requests 2.32.5+dfsg-2 (source) into unstable (Alexandre Detiste)
  • [2026-03-08] Accepted requests 2.32.3+dfsg-5+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-09-13] requests 2.32.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-29] Accepted requests 2.32.5+dfsg-1 (source) into unstable (Colin Watson)
  • [2025-08-23] requests 2.32.4+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-18] Accepted requests 2.32.4+dfsg-1 (source) into unstable (Colin Watson)
  • [2025-04-17] requests 2.32.3+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2025-03-24] Accepted requests 2.32.3+dfsg-5 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-02-23] requests 2.32.3+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2025-02-17] Accepted requests 2.32.3+dfsg-4 (source) into unstable (Colin Watson)
  • [2025-02-17] Accepted requests 2.32.3+dfsg-3 (source) into experimental (Colin Watson)
  • [2024-11-24] Accepted requests 2.32.3+dfsg-2 (source) into experimental (Alexandre Detiste)
  • [2024-08-31] requests 2.32.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-13] Accepted requests 2.32.3+dfsg-1 (source) into unstable (Colin Watson)
  • [2024-05-19] requests 2.31.0+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2024-05-16] Accepted requests 2.31.0+dfsg-2 (source) into unstable (Timo Röhling)
  • [2023-07-22] requests 2.31.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-07-17] Accepted requests 2.31.0+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2023-06-18] Accepted requests 2.21.0-1+deb10u1 (source) into oldoldstable (Markus Koschany)
  • [2022-11-26] requests 2.28.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-24] Accepted requests 2.28.1+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2022-03-31] requests 2.27.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-20] Accepted requests 2.27.1+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2021-01-06] requests 2.25.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2020-12-31] Accepted requests 2.25.1+dfsg-2 (source) into unstable (Daniele Tricoli)
  • [2020-12-31] Accepted requests 2.25.1+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2020-12-30] Accepted requests 2.25.0+dfsg-2 (source) into unstable (Daniele Tricoli)
  • [2020-12-08] Accepted requests 2.25.0+dfsg-1 (source) into unstable (Daniele Tricoli)
  • 1
  • 2
bugs [bug history graph]
  • all: 9
  • RC: 0
  • I&N: 7
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.34.2-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing