
Impact Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Workarounds For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on your Requests Session (docs). References https://github.com/psf/requests/pull/6965…Read More
Requests vulnerable to .netrc credentials leak via malicious URLs

