request / request

🏊🏾 Simplified HTTP request client.
Apache License 2.0
25.67k stars 3.14k forks source link

Issue on a dependency - CVE-2023-26136 #3476

Closed Reni88 closed 2 months ago

Reni88 commented 5 months ago

Hi,

Good day. Just wanted to inform that we encountered a security issue on one of request dependency for its version 2.88.2:

Dependency: tough-cookie Version: 2.5.0

It is raised under this CVE ID: CVE-2023-26136

If this was already discussed and resolution was already delivered. Let us know. Thank you.

mtarek2005 commented 2 months ago

still unchanged... the weekly downloads are too much for this bad of a vulnerability, log4shell again?

Reni88 commented 2 months ago

Hi, As this package has been deprecated. We decided to just migrate to an alternative. Closing this now.