{"sample":true,"fixed_snapshot":true,"schema_version":1,"checked_at":"2026-10-03T00:48:33.692Z","requested":{"name":"requests","version":"2.31.0"},"package":{"name":"requests","release_version":"2.31.0","current_pypi_version":"2.34.2","requires_python":">=3.7","dependencies":["charset-normalizer (<4,>=2)","idna (<4,>=2.5)","urllib3 (<3,>=1.21.1)","certifi (>=2017.4.17)","PySocks (!=1.5.7,>=1.5.6) ; extra == 'socks'","chardet (<6,>=3.0.2) ; extra == 'use_chardet_on_py3'"],"metadata_license_expression":null},"distributions":{"file_count":2,"wheel_count":1,"source_count":1,"all_files_yanked":false,"files":[{"filename":"requests-2.31.0-py3-none-any.whl","type":"bdist_wheel","size_bytes":62574,"sha256":"58cd2187c01e70e6e26505bca751777aa9f2ee0b7f4300988b709f44e013003f","uploaded_at":"2023-05-22T15:12:42.313790Z","requires_python":">=3.7","yanked":false,"yanked_reason":null,"wheel_tags":{"python":["py3"],"abi":["none"],"platform":["any"]}},{"filename":"requests-2.31.0.tar.gz","type":"sdist","size_bytes":110794,"sha256":"942c5a758f98d790eaed1a29cb6eefc7ffb0d1cf7af05c3d2791656dbd6ad1e1","uploaded_at":"2023-05-22T15:12:44.175995Z","requires_python":">=3.7","yanked":false,"yanked_reason":null,"wheel_tags":null}]},"known_advisories":{"count":6,"query":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.31.0"},"complete":true,"advisories":[{"id":"GHSA-9hjg-9r4m-mvj7","aliases":["CVE-2024-47081","PYSEC-2026-1872"],"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","fixed_versions_reported":["2.32.4"],"affected_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.32.4"}]}],"source":"https://osv.dev/vulnerability/GHSA-9hjg-9r4m-mvj7"},{"id":"GHSA-9wx4-h78v-vm56","aliases":["CVE-2024-35195","PYSEC-2026-1873"],"summary":"Requests `Session` object does not verify requests after making first request with verify=False","fixed_versions_reported":["2.32.0"],"affected_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.32.0"}]}],"source":"https://osv.dev/vulnerability/GHSA-9wx4-h78v-vm56"},{"id":"GHSA-gc5v-m9x4-r6x2","aliases":["CVE-2026-25645","PYSEC-2026-2275"],"summary":"Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function","fixed_versions_reported":["2.33.0"],"affected_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.33.0"}]}],"source":"https://osv.dev/vulnerability/GHSA-gc5v-m9x4-r6x2"},{"id":"PYSEC-2026-1872","aliases":["CVE-2024-47081","GHSA-9hjg-9r4m-mvj7"],"summary":"Requests vulnerable to .netrc credentials leak via malicious URLs","fixed_versions_reported":["2.32.4"],"affected_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.32.4"}]}],"source":"https://osv.dev/vulnerability/PYSEC-2026-1872"},{"id":"PYSEC-2026-1873","aliases":["CVE-2024-35195","GHSA-9wx4-h78v-vm56"],"summary":"Requests `Session` object does not verify requests after making first request with verify=False","fixed_versions_reported":["2.32.0"],"affected_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.32.0"}]}],"source":"https://osv.dev/vulnerability/PYSEC-2026-1873"},{"id":"PYSEC-2026-2275","aliases":["CVE-2026-25645","GHSA-gc5v-m9x4-r6x2"],"summary":null,"fixed_versions_reported":["2.33.0"],"affected_ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.33.0"}]}],"source":"https://osv.dev/vulnerability/PYSEC-2026-2275"}]},"minimum_checked_upgrade_version":"2.33.0","upgrade_check":{"status":"clear_upgrade_found","candidate_limit":8,"eligible_release_count":9,"checked_versions":[{"version":"2.32.2","advisory_count":4,"query":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.2"},"observations":[{"body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.2"},"checked_at":"2026-10-03T00:48:32.654Z"}],"complete":true},{"version":"2.32.3","advisory_count":4,"query":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.3"},"observations":[{"body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.3"},"checked_at":"2026-10-03T00:48:32.925Z"}],"complete":true},{"version":"2.32.4","advisory_count":2,"query":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.4"},"observations":[{"body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.4"},"checked_at":"2026-10-03T00:48:33.184Z"}],"complete":true},{"version":"2.32.5","advisory_count":2,"query":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.5"},"observations":[{"body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.32.5"},"checked_at":"2026-10-03T00:48:33.454Z"}],"complete":true},{"version":"2.33.0","advisory_count":0,"query":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.33.0"},"observations":[{"body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.33.0"},"checked_at":"2026-10-03T00:48:33.691Z"}],"complete":true}],"scope":"Higher non-yanked PyPI releases using numeric PEP 440 epoch/release components only; excludes pre, post, dev and local versions. OSV exact-version checks, not dependency or runtime compatibility.","osv_query_url":"https://api.osv.dev/v1/query","minimum_within_scope":true},"sources":{"project":"https://pypi.org/pypi/requests/json","release":"https://pypi.org/pypi/requests/2.31.0/json","osv_query":{"url":"https://api.osv.dev/v1/query","method":"POST","body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.31.0"},"observations":[{"body":{"package":{"name":"requests","ecosystem":"PyPI"},"version":"2.31.0"},"checked_at":"2026-10-03T00:48:32.350Z"}]},"documentation":["https://docs.pypi.org/api/json/","https://google.github.io/osv.dev/api/","https://packaging.python.org/en/latest/specifications/version-specifiers/"]},"limits":["Publisher metadata, not inspected distribution contents.","Wheel tags are reported, not proof of runtime compatibility.","Only OSV exact-version matches at check time; zero matches is not a safety verdict.","The upgrade field checks at most eight higher non-yanked numeric final releases in order, excludes pre/post/dev/local versions, and is not a minimum-safe-version or compatibility guarantee. Null means no target established; inspect upgrade_check.status.","No dependency resolution, package installation or code execution."]}