PyPI package intelligence

requests — deep security report

ShadowCanopy's full breakdown of requests on PyPI: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 8/19/2026
Approvedrequests@2.32.3View on registry ↗latest: 2.32.3

This is the legitimate, well-known 'requests' HTTP library (v2.32.3) with zero static findings and only standard package files present. No malicious behavior indicated.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

The 'requests' package is a Python HTTP library described as 'Python HTTP for Humans.' It provides modules for making HTTP requests, handling sessions, authentication, cookies, and related utilities.

Capabilities

  • Makes HTTP requests
  • Manages sessions and cookies
  • Handles authentication
  • Provides status codes and exceptions

Data access

  • Filesystem (certs.py present)
  • Environment variables (not observed in manifest)

Network

  • Makes outbound HTTP requests

Widely used benign library with no scripts or dependencies in manifest and no static findings; standard HTTP client behavior expected.

Dependency & execution chain

Every package this one pulls in, colored by verdict. Expand to walk the tree.

10 packages5 direct
requests@2.32.3
charset_normalizer@3.5.110 findings
idna@3.196 findings
urllib3@2.7.040 findings
certifi@2026.7.22

Known vulnerabilities (4)

Published CVEs / advisories affecting this version.

GHSA-9hjg-9r4m-mvj7MODERATE

Requests vulnerable to .netrc credentials leak via malicious URLs

GHSA-gc5v-m9x4-r6x2MODERATE

Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function

PYSEC-2026-1872UNKNOWN

Requests vulnerable to .netrc credentials leak via malicious URLs

PYSEC-2026-2275UNKNOWN

Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded i

Package metadata

LicenseApache-2.0

Python HTTP for Humans.

Homepage ↗

Files in package (166)

HISTORY.mdrequests-2.32.3/HISTORY.mdLICENSErequests-2.32.3/LICENSEMANIFEST.inrequests-2.32.3/MANIFEST.inNOTICErequests-2.32.3/NOTICEPKG-INFOrequests-2.32.3/PKG-INFOREADME.mdrequests-2.32.3/README.mdpyproject.tomlrequests-2.32.3/pyproject.tomlrequirements-dev.txtrequests-2.32.3/requirements-dev.txtsetup.cfgrequests-2.32.3/setup.cfgsetup.pyrequests-2.32.3/setup.pysrc/requests/__init__.pyrequests-2.32.3/src/requests/__init__.pysrc/requests/__version__.pyrequests-2.32.3/src/requests/__version__.pysrc/requests/_internal_utils.pyrequests-2.32.3/src/requests/_internal_utils.pysrc/requests/adapters.pyrequests-2.32.3/src/requests/adapters.pysrc/requests/api.pyrequests-2.32.3/src/requests/api.pysrc/requests/auth.pyrequests-2.32.3/src/requests/auth.pysrc/requests/certs.pyrequests-2.32.3/src/requests/certs.pysrc/requests/compat.pyrequests-2.32.3/src/requests/compat.pysrc/requests/cookies.pyrequests-2.32.3/src/requests/cookies.pysrc/requests/exceptions.pyrequests-2.32.3/src/requests/exceptions.py

How ShadowCanopy checks PyPI packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/pypi/requests