Skip to content

fix(deps): bump requests to 2.32.4 - #438

Merged
JefferyHcool merged 1 commit into
JefferyHcool:masterfrom
katsugtgz:fix/requests-cve-2024-47081
Aug 11, 2026
Merged

fix(deps): bump requests to 2.32.4#438
JefferyHcool merged 1 commit into
JefferyHcool:masterfrom
katsugtgz:fix/requests-cve-2024-47081

Conversation

@katsugtgz

Copy link
Copy Markdown

Summary

Bumps requests from 2.32.3 to 2.32.4 in backend/requirements.txt.

Vulnerability addressed

Relates to #395.

Scanner evidence

  • Before patch (2.32.3): osv-scanner reported PYSEC-2026-1872 / GHSA-9hjg-9r4m-mvj7 for requests==2.32.3.
  • After patch (2.32.4): PYSEC-2026-1872 / GHSA-9hjg-9r4m-mvj7 is no longer reported.

Remaining advisory: PYSEC-2026-2275 (CVE-2026-25645, GHSA-gc5v-m9x4-r6x2) still affects requests==2.32.4 — fixed in 2.33.0. A separate bump may be needed.

Changed files

  • backend/requirements.txt (1 line: requests==2.32.3requests==2.32.4)

No application logic or source behavior changed.

@JefferyHcool
JefferyHcool merged commit f58e618 into JefferyHcool:master Aug 11, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants