FlawAtlas
Search the atlas
CVE-2014-1829 Moderate

CVE-2014-1829

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

Exploit probability 2.2%
Published October 15, 2014
Required by Not available
Last source change April 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI requests

84 explicit affected versions

PyPI requests

84 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2014-1829

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

View original source
Open Source Vulnerabilities GHSA-cfj3-7x9c-4p3h

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

View original source
Open Source Vulnerabilities PYSEC-2014-13

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

View original source

05 / REFERENCES

Further evidence