requests is vulnerable to information disclosure attacks. The HTTP Authorization header is sent via insecure HTTP channel when a same-hostname HTTPS-to-HTTP redirect is received, allowing remote attackers in the same network to discover credentials by sniffing the network traffic.
docs.python-requests.org/en/master/community/updates/#release-and-version-history
lists.opensuse.org/opensuse-security-announce/2019-07/msg00024.html
access.redhat.com/errata/RHSA-2019:2035
bugs.debian.org/910766
github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff
github.com/requests/requests/issues/4716
github.com/requests/requests/pull/4718
usn.ubuntu.com/3790-1/
usn.ubuntu.com/3790-2/
www.oracle.com/security-alerts/cpujul2022.html