NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #7 most downloaded on PyPI
Python HTTP for Humans.
Last release 4 months ago
14 May 2026
Release timing varies
gaps range from 8 days to 13 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
16 years old
163 releases · first in 2011
Moved headers input type back to Mapping to avoid invariance issues with MutableMapping and inferred dict types. Users calling Request.headers.update(
headers input type back to Mapping to avoid invariance issues with MutableMapping and inferred dict types. Users calling Request.headers.update() may need to narrow typing in their code. (#7441)Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14
Widened json input type from dict and list to Mapping and Sequence .
Bugfixes
json input type from dict and list to MappingSequence. (#7436)headers input type to MutableMapping and removed None fromRequest.headers typing to improve handling for users. (#7431)Response.reason moved from str | None to str to improve handling__getattr__ implementationsFull Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13
One column per quarter.
Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty.
Announcements
Requests 2.34.0 introduces inline types, replacing those provided by
typeshed. Public API types should be fully compatible with mypy, pyright,
and ty. We believe types are comprehensive but if you find issues, please
report them to the pinned tracking issue.
Special thanks to @bastimeyer, @cthoyt, @edgarrmondragon, and @srittau for
helping review and test the types ahead of the release. (#7272)
Improvements
usedforsecurity=False to clarifyBugfixes
Response.history no longer contains a reference to itself, preventingFull Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2340-2026-05-11
Nothing published for this version
Fixed test cleanup for CVE-2026-25645 to avoid leaving unnecessary files in the tmp directory.
Bugfixes
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2331-2026-03-30
CVE-2026-25645 requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This d…
Announcements
Security
requests.utils.extract_zipped_paths now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.Improvements
Bugfixes
Deprecations
Documentation
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25
The SSLContext caching feature originally introduced in 2.32.0 has created a new class of issues in Requests that have had negative impact across a nu
Bugfixes
Deprecations
CVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted environment will retrieve credentials for the wrong hostname/machine from a…
Security
Improvements
Deprecations
Fixed bug breaking the ability to specify custom SSLContexts in sub-classes of HTTPAdapter.
…is subject to the same issue described in CVE-2024-35195 .
Deprecations
To provide a more stable migration for custom HTTPAdapters impacted
by the CVE changes in 2.32.0, we've renamed _get_connection to
a new public API, get_connection_with_tls_context. Existing custom
HTTPAdapters will need to migrate their code to use this new API.
get_connection is considered deprecated in all versions of Requests>=2.32.0.
A minimal (2-line) example has been provided in the linked PR to ease
migration, but we strongly urge users to evaluate if their custom adapter
is subject to the same issue described in CVE-2024-35195. (#6710)
Add missing test certs to the sdist distributed on PyPI.
Bugfixes
Fixed an issue where setting verify=False on the first request from a Session will cause subsequent requests to the _same origin_ to also ignore cert
Security
verify=False on the first request from a
Session will cause subsequent requests to the same origin to also ignore
cert verification, regardless of the value of verify.
(https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56)Improvements
verify=True now reuses a global SSLContext which should improve
request time variance between first and subsequent requests. It should
also minimize certificate load time on Windows systems when using a Python
version built with OpenSSL 3.x. (#6667)chardet or charset_normalizer) when repackaged or vendored.
This enables pip and other projects to minimize their vendoring
surface area. The Response.text() and apparent_encoding APIs
will default to utf-8 if neither library is present. (#6702)Bugfixes
/ (path separator) could lead
urllib3 to unnecessarily reparse the request URI. (#6644)Deprecations
Documentation
Packaging
requests) is now located
in src/requests in the Requests sdist. (#6506)hatchling. This should not impact the average user, but extremely old
versions of packaging utilities may have issues with the new packaging format.Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2320-2024-05-20
Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential forwarding of Proxy-Authorization headers to destination servers when foll…
Security
Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential
forwarding of Proxy-Authorization headers to destination servers when
following HTTPS redirects.
When proxies are defined with user info (https://user:pass@proxy:8080), Requests
will construct a Proxy-Authorization header that is attached to the request to
authenticate with the proxy.
In cases where Requests receives a redirect response, it previously reattached
the Proxy-Authorization header incorrectly, resulting in the value being
sent through the tunneled connection to the destination server. Users who rely on
defining their proxy credentials in the URL are strongly encouraged to upgrade
to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy
credentials once the change has been fully deployed.
Users who do not use a proxy or do not supply their proxy credentials through the user information portion of their proxy URL are not subject to this vulnerability.
Full details can be read in our Github Security Advisory and CVE-2023-32681.
This may contain minor breaking changes so we advise careful testing and reviewing https://urllib3.readthedocs.io/en/latest/v2-migration-guide.html pr…
Dependencies
⚠️ Added support for urllib3 2.0. ⚠️
This may contain minor breaking changes so we advise careful testing and reviewing https://urllib3.readthedocs.io/en/latest/v2-migration-guide.html prior to upgrading.
Users who wish to stay on urllib3 1.x can pin to urllib3<2.
Requests now defers chunked requests to the urllib3 implementation to improve standardization.
Improvements
Requests now supports charset\_normalizer 3.x.
Dependencies
Bugfixes
Full Changelog: https://github.com/psf/requests/compare/v2.28.1...v2.28.2
Speed optimization in iter_content with transition to yield from.
Improvements
iter_content with transition to yield from. (#6170)Dependencies
Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2281-2022-06-29
⚠️ Requests has officially dropped support for Python 2.7. ⚠️
Deprecations
Improvements
json() API consistent. (#6097)Bugfixes
CURL_CA_BUNDLE to an empty string would disable
cert verification. All Requests 2.x versions before 2.28.0 are affected. (#6074)urllib3.exceptions.SSLError with
requests.exceptions.SSLError for content and iter_content. (#6057)Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2280-2022-06-09
Fixed parsing issue that resulted in the auth component being dropped from proxy URLs.
Bugfixes
auth component being
dropped from proxy URLs. (#6028)Full Changelog: https://github.com/psf/requests/blob/v2.27.1/HISTORY.md#2271-2022-01-05
Officially added support for Python 3.10.
Improvements
Officially added support for Python 3.10. (#5928)
Added a requests.exceptions.JSONDecodeError to unify JSON exceptions between
Python 2 and 3. This gets raised in the response.json() method, and is
backwards compatible as it inherits from previously thrown exceptions.
Can be caught from requests.exceptions.RequestException as well. (#5856)
Improved error text for misnamed InvalidSchema and MissingSchema
exceptions. This is a temporary fix until exceptions can be renamed
(Schema->Scheme). (#6017)
Improved proxy parsing for proxy URLs missing a scheme. This will address
recent changes to urlparse in Python 3.9+. (#5917)
Bugfixes
Fixed defect in extract_zipped_paths which could result in an infinite loop
for some paths. (#5851)
Fixed handling for AttributeError when calculating length of files obtained
by Tarfile.extractfile(). (#5239)
Fixed urllib3 exception leak, wrapping urllib3.exceptions.InvalidHeader with
requests.exceptions.InvalidHeader. (#5914)
Fixed bug where two Host headers were sent for chunked requests. (#5391)
Fixed regression in Requests 2.26.0 where Proxy-Authorization was
incorrectly stripped from all requests sent with Session.send. (#5924)
Fixed performance regression in 2.26.0 for hosts with a large number of proxies available in the environment. (#5924)
Fixed idna exception leak, wrapping UnicodeError with
requests.exceptions.InvalidURL for URLs with a leading dot (.) in the
domain. (#5414)
Deprecations
Full Changelog: https://github.com/psf/requests/blob/v2.27.0/HISTORY.md#2270-2022-01-03
Requests now supports Brotli compression, if either the brotli or brotlicffi package is installed.
Improvements
Requests now supports Brotli compression, if either the brotli or
brotlicffi package is installed. (#5783)
Session.send now correctly resolves proxy configurations from both
the Session and Request. Behavior now matches Session.request. (#5681)
Bugfixes
Dependencies
Instead of chardet, use the MIT-licensed charset_normalizer for Python3
to remove license ambiguity for projects bundling requests. If chardet
is already installed on your machine it will be used instead of charset_normalizer
to keep backwards compatibility. (#5797)
You can also install chardet while installing requests by
specifying [use_chardet_on_py3] extra as follows:
pip install "requests[use_chardet_on_py3]"
Python2 still depends upon the chardet module.
Requests now supports idna 3.x on Python 3. idna 2.x will continue to
be used on Python 2 installations. (#5711)
Deprecations
The requests[security] extra has been converted to a no-op install.
PyOpenSSL is no longer the recommended secure option for Requests. (#5867)
Requests has officially dropped support for Python 3.5. (#5867)
Requests now treats application/json as utf8 by default. Resolving inconsistencies between r.text and r.json output.
Bugfixes
application/json as utf8 by default. Resolving
inconsistencies between r.text and r.json output. (#5673)Dependencies
The requests[security] extra is officially deprecated and will be removed in Requests v2.26.0.
Improvements
Dependencies
Deprecations
requests[security] extra is officially deprecated and will be removed
in Requests v2.26.0.pyOpenSSL TLS implementation is now only used if Python either doesn't have an ssl module or doesn't support SNI. Previously pyOpenSSL was uncondition
Improvements
pyOpenSSL TLS implementation is now only used if Python
either doesn't have an ssl module or doesn't support
SNI. Previously pyOpenSSL was unconditionally used if available.
This applies even if pyOpenSSL is installed via the
requests[security] extra (#5443)
Redirect resolution should now only occur when
allow_redirects is True. (#5492)
No longer perform unnecessary Content-Length calculation for requests that won't use it. (#5496)
Remove defunct reference to prefetch in Session __attrs__
Improvements
prefetch in Session __attrs__ (#5110)Bugfixes
Dependencies
chardet and idna now uses major version instead of minor.
This hopefully reduces the need for releases every time a dependency is updated.Requests now supports urllib3 v1.25.2. (note: 1.25.0 and 1.25.1 are incompatible)
Dependencies
Deprecations
Requests now supports idna v2.8.
Dependencies
Fixed bug with unintended Authorization header stripping for redirects using default ports (http/80, https/443).
Bugfixes
Requests removes Authorization header from requests redirected from https to http on the same hostname. (CVE-2018-18074)
Bugfixes
should_bypass_proxies now handles URIs without hostnames (e.g.
files).Dependencies
Deprecations
Fixed issue where status\_codes.py's init function failed trying to append to a __doc__ value of None.
Bugfixes
init function failed trying
to append to a __doc__ value of None.Warn user about possible slowdown when using cryptography version < 1.3.4
Improvements
Request.content.Bugfixes
Link headers with parse_header_links() no longer
return one bogus entry.IOError.ImportError on windows system which do
not support winreg module.None as a file pointer to the files param no longer
raises an exception.copy on a RequestsCookieJar will now preserve the cookie
policy correctly.Dependencies
Error messages for invalid headers now include the header name for easier debugging
Improvements
Dependencies
Running $ python -m requests.help now includes the installed version of idna.
Improvements
$ python -m requests.help now includes the installed
version of idna.Bugfixes
ConnectionError instead of
SSLError when encountering SSL problems when using urllib3 v1.22.requests.help no longer fails on Python 2.6 due to the absence of ssl.OPENSSL_VERSION_NUMBER.
Bugfixes
requests.help no longer fails on Python 2.6 due to the absence of
ssl.OPENSSL_VERSION_NUMBER.Dependencies
Fix an error in the packaging whereby the *.whl contained incorrect data that regressed the fix in v2.17.3.
Bugfixes
*.whl contained
incorrect data that regressed the fix in v2.17.3.Response is now a context manager, so can be used directly in a with statement without first having to be wrapped by contextlib.closing().
Improvements
Response is now a context manager, so can be used directly in a
with statement without first having to be wrapped by
contextlib.closing().Bugfixes
Improved packages namespace identity support, for monkeypatching libraries.
Improvements
packages namespace identity support, for monkeypatching
libraries.Improved packages namespace identity support, for monkeypatching libraries.
Improvements
packages namespace identity support, for monkeypatching
libraries.Improved packages namespace identity support, for monkeypatching libraries.
Improvements
packages namespace identity support, for monkeypatching
libraries.Removal of the 301 redirect cache. This improves thread-safety.
Improvements
Improvements to $ python -m requests.help.
$ python -m requests.help.Introduction of the $ python -m requests.help command, for debugging with maintainers!
$ python -m requests.help command, for
debugging with maintainers!Further restored the requests.packages namespace for compatibility reasons.
requests.packages namespace for compatibility
reasons.Further restored the requests.packages namespace for compatibility reasons.
requests.packages namespace for compatibility
reasons.No code modification (noted below) should be necessary any longer.
Restored the requests.packages namespace for compatibility reasons.
requests.packages namespace for compatibility
reasons.urllib3 version parsing.Note: code that was written to import against the
requests.packages namespace previously will have to import code that
rests at this module-level now.
For example:
from requests.packages.urllib3.poolmanager import PoolManager
Will need to be re-written to be:
from requests.packages import urllib3
urllib3.poolmanager.PoolManager
Or, even better:
from urllib3.poolmanager import PoolManager
- Unvendor ALL the things!
- Everyone makes mistakes.
Introduction of the Response.next property, for getting the next PreparedResponse from a redirect chain (when allow_redirects=False).
Improvements
Response.next property, for getting the next
PreparedResponse from a redirect chain (when
allow_redirects=False).__version__ module.Bugfixes
requests.utils.get_environ_proxies().Changed a less-than to an equal-to and an or in the dependency markers to widen compatibility with older setuptools releases.
Bugfixes
Changed the dependency markers to widen compatibility with older pip releases.
Bugfixes
Fixed some code that was firing DeprecationWarning on Python 3.6.
Improvements
no_proxy as a key to the proxies
dictionary to provide handling similar to the NO_PROXY environment
variable.IOError, rather than failing at
the time of the HTTPS request with a fairly inscrutable certificate
validation error.SessionRedirectMixin was slightly altered.
resolve_redirects will now detect a redirect by calling
get_redirect_target(response) instead of directly querying
Response.is_redirect and Response.headers['location']. Advanced
users will be able to process malformed redirects more easily.win_inet_pton as conditional dependency for the [socks]
extra on Windows with Python 2.7.http but are not http or
https no longer have their host parts forced to lowercase.Bugfixes
Location header values in
redirects. Fewer UnicodeDecodeErrors are encountered on Python 2,
and Python 3 now correctly understands that Latin-1 is unlikely to
be the correct encoding.seek file to find out its length fails, we now
appropriately handle that by aborting our content-length
calculations.HTTPDigestAuth to only respond to auth challenges made
on 4XX responses, rather than to all auth challenges.DeprecationWarning on Python 3.6./o\\) no longer has a big head. I'm
sure this is what you were all worrying about most.Miscellaneous
Only load the idna library when we've determined we need it. This will save some memory for users.
Features
idna library when we've determined we need it. This
will save some memory for users.Miscellaneous
Fixed an issue with JSON encoding detection, specifically detecting big-endian UTF-32 with BOM.
Bugfixes
While support for this behaviour has been re-added, the behaviour is deprecated and will be removed in the future.
Bugfixes
Fixed regression from v2.12.1 for URLs with schemes that begin with "http". These URLs have historically been processed as though they were HTTP-schem
Bugfixes
Fixed several issues with IDNA-encoding URLs that are technically invalid but which are widely accepted. Requests will now attempt to IDNA-encode a UR
Bugfixes
InvalidSchema errors.Response.content to
raise an AttributeError.Updated setuptools 'security' extra for the new PyOpenSSL backend in urllib3.
Bugfixes
Miscellaneous
Updated support for internationalized domain names from IDNA2003 to IDNA2008. This updated support is required for several forms of IDNs and is mandat
Improvements
StringIO into memory.Content-Length headers for
PreparedRequest objects.tell method
but do have a seek method.Mapping is now treated like a
dictionary by the data= keyword argument.Bugfixes
response.close, the call to close will be
propagated through to non-urllib3 backends.ALL_PROXY environment variable would be
preferred over scheme-specific variables like HTTP_PROXY.Miscellaneous
Fixed a bug when using iter_content with decode_unicode=True for streamed bodies would raise AttributeError. This bug was introduced in 2.11.
Bugfixes
iter_content with decode_unicode=True for
streamed bodies would raise AttributeError. This bug was
introduced in 2.11.Added support for the ALL_PROXY environment variable.
Improvements
ALL_PROXY environment variable.Bugfixes
TypeError when attempting to decode a JSON
response that occurred in an error case. Now correctly returns a
ValueError.NO_PROXY environment variables: Requests now treats it as a
specific IP.iter_content only accepts
integers and None for chunk sizes.HTTPAdapter had been configured to use a blocking
connection pool.Miscellaneous
Your coding agent can read these notes before it upgrades. Set up the MCP server →