
JUST IN: Fedora 43 patches CVE-2026-25645 in python-requests and python-pulp-glue, fixing non-deterministic extraction that could allow malicious file replacement. https://threatcluster.io/cluster/critical-bugfix-for-cve-2026-25645-in-fedora-packages-da23c6b6
Post summary
Fedora 43 released a patch for CVE-2026-25645 in python-requests and python-pulp-glue, fixing a non‑deterministic extraction flaw that could enable malicious file replacement.


