Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 44 python-pulp-glue Important CVE-2026-25645 Malformed Header Fix

fedora
Calendar Grey May 10, 2026
Dist Fedora Esm H88
Stay secure with Fedora 44 Python Pulp Glue critical update addressing CVE-2026-25645 and improving bug fixes.
2.33.1 (2026-03-30) Bugfixes - Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory

Summary

pulp-glue is a library to ease the programmatic communication with the Pulp3

API. It helps to abstract different resource types with so called contexts and

allows to build or even provides complex workflows like chunked upload or

waiting on tasks.

It is built around an openapi3 parser to provide client side validation of http

requests, while accounting for known quirks and incompatibilities between

different Pulp server component versions.

Update Information:

2.33.1 (2026-03-30) Bugfixes - Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory. - Fixed Content-Type header parsing for malformed values. - Improved error consistency for malformed header values. 2.33.0 (2026-03-25) Announcements - \U0001f4e3 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at #7271. Give it a try, and report any gaps or feedback you may have in the issue. \U0001f4e3 Security - CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly. Improvements - Migrated to a PEP 517 build system using setuptools. Bugfixes - Fixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. Deprecations - Dropped support for Pyt...

Change Log

* Thu Apr 2 2026 Lumir Balhar - 0.37.0-5 - Remove upper version bound on requests * Tue Feb 17 2026 Simone Caronni - 0.37.0-4 - Clean up .gitignore

References


[ 1 ] Bug #2467989 - python3-requests package lacks fix for CVE-2026-25645 https://bugzilla.redhat.com/show_bug.cgi?id=2467989

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-44919b3d9f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-pulp-glue
Product: Fedora 44
Version: 0.37.0
Release: 5.fc44
Summary: The version agnostic Pulp 3 client library in python

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here