🛡️ USN-7762-1 — python-pip
Description
python-pip vulnerabilities
Dennis Brinkrolf and Tobias Funke discovered that Requests incorrectly
leaked Proxy-Authorization headers. A remote attacker could possibly use
this issue to obtain sensitive information. This update addresses the issue
in the Requests module bundled into pip in Ubuntu 22.04 LTS.
(CVE-2023-32681)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This update
addresses the issue in the urllib3 module bundled into pip in Ubuntu
24.04 LTS. (CVE-2023-45803)
Guido Vranken discovered that idna did not properly manage certain inputs,
which could lead to significant resource consumption. An attacker could
possibly use this issue to cause a denial of service. This update addresses
the issue in the idna module bundled into pip in Ubuntu 22.04 LTS and
Ubuntu 24.04 LTS. (CVE-2024-3651)
Juho Forsén discovered that Requests did not correctly parse URLs. A
remote attacker could possibly use this issue to leak sensitive
information. This update addresses the issue in the Requests module bundled
into pip in Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2024-47081)
Affected software
USN-7762-1 is recorded against 1 package.
- python-pip (fixed in 24.0+dfsg-1ubuntu1.3)
Timeline and source
Published on 23 September 2025 and last revised on 27 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
launchpad.net (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| python-pip | — | 24.0+dfsg-1ubuntu1.3 |
References
Similar Threats
- Unknown ECHO-7b00-1c82-cbfb
- Unknown DEBIAN-CVE-2026-13346
- Unknown DEBIAN-CVE-2026-8643
- Unknown ECHO-0a2a-4462-0b2a
- Unknown DEBIAN-CVE-2026-6357
More USN 7 advisories
Browse all of USN 7 in the advisory index.
Free Vulnerability Check
Is your site affected by USN-7762-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-7762-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.