CVE-2026-25645
Publication date 25 March 2026
Last updated 28 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.
Read the notes from the security team
Why is this CVE low priority?
Nothing in Ubuntu uses the affected function directly
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| requests | 26.04 LTS resolute |
Fixed 2.32.5+dfsg-1ubuntu1.1
|
| 24.04 LTS noble |
Fixed 2.31.0+dfsg-1ubuntu1.2
|
|
| 22.04 LTS jammy |
Fixed 2.25.1+dfsg-2ubuntu0.4
|
|
| 20.04 LTS focal |
Fixed 2.22.0-2ubuntu1.1+esm2
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|
| python-pip | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
mdeslaur
On focal and earlier, the python-pip package bundles requests binaries when built. After updating requests, a no-change rebuild of python-pip is required. On jammy and later, requests is bundled in the python-pip package and needs to be patched. the extract_zipped_paths() function is only used to extract CA bundles provided in zip format. Nothing in the archive uses extract_zipped_paths() directly. Marking this issue as being low priority.
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.4 · Medium
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
References
Related Ubuntu Security Notices (USN)
- USN-8825-1
- Requests vulnerability
- 28 September 2026