On 2026-06-30 09:41:01 [+0000], Debian Bug Tracking System wrote: > requests (2.34.2-1) unstable; urgency=medium … > * New upstream version 2.34.2 > Fixed CVE issue(s) in upstream version 2.33 > CVE-2026-25645: Insecure Temp File Reuse in extract_zipped_paths() > (Closes: #1132071, #1138296)
Was closing #1138296 accurate here? I tried to rebuild requests_2.34.2-1 against openssl 4.0 and the fallout looked the same as in the initial report. Sebastian

