CVE-2026-25645 | psf requests up to 2.32.x requests.utils.extract_zipped_paths temp file (GHSA-gc5v-m9x4-r6x2 / Nessus ID 303843)
A vulnerability described as problematic has been identified in psf requests up to 2.32.x. This impacts the function requests.utils.extract_zipped_paths. The manipulation results in insecure temporary file.
This vulnerability is cataloged as CVE-2026-25645. The attack must be initiated from a local position. There is no exploit available.
Upgrading the affected component is recommended.