Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-35195
Description:Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.
Test IDs: 1.3.6.1.4.1.25623.1.0.886902   1.3.6.1.4.1.25623.1.0.856277   1.3.6.1.4.1.25623.1.0.887121   1.3.6.1.4.1.25623.1.1.4.2024.1880.2   1.3.6.1.4.1.25623.1.0.856199   1.3.6.1.4.1.25623.1.1.4.2024.2068.1   1.3.6.1.4.1.25623.1.0.856372   1.3.6.1.4.1.25623.1.0.856179   1.3.6.1.4.1.25623.1.0.856205   1.3.6.1.4.1.25623.1.1.10.2024.0210  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-35195
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ/
https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac
https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac
https://github.com/psf/requests/pull/6655
https://github.com/psf/requests/pull/6655
https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56
https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56




© 1998-2025 E-Soft Inc. All rights reserved.