VDB

GCVE-110-OSM-2026-8428

GCVE-110-OSM-2026-8428
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 17, 2026
Suspicious package detected. Behaviors: data exfiltration, code execution. ENTRY requests/__init__.py (module-import: 111) DESTINATION - custom-c2: https://{url (primary, plaintext) in requests/models.py - custom-c2: https://pepy.tech/project/requests (plaintext) in requests_testik11-2.33.0.dist-info/METADATA - custom-c2: https://kennethreitz.org (plaintext) in requests_testik11-2.33.0.dist-info/METADATA - custom-c2: static.pepy.tech (plaintext) in requests_testik11-2.33.0.dist-info/METADATA - custom-c2: pepy.tech (plaintext) in requests_testik11-2.33.0.dist-info/METADATA EXFIL - Network Request in requests/__init__.py: "requests.get(" - Network Request in requests/api.py: "request('GET', 'https:" - System Information Collection in requests/help.py: "platform.system()" - Network Request in requests/models.py: "Request('GET', 'https:" - Network Request in requests_testik11-2.33.0.dist-info/METADATA: "requests.get(" PAYLOAD FILES requests/help.py (+ requests/__init__.py, requests/api.py) INDICATORS (IOCs) - ipv6: 1:: - urls: http://domain.tld/path/to/resource, http://host.name, https://www.ietf.org/rfc/rfc4627.txt - domains: kennethreitz.org, www.ietf.org - emails: me@kennethreitz.org - payloadFileHash: bccadffb7379b8e92c9c5a2a4cb1f36c66f7570dbb5b085d85d04984fe652fed

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownrequests-testik11all (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›