Unserialization of untrusted data.
The issue has been patched and users of Requests 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
Publications about the vulnerability:
Originally fixed in WordPress 5.5.2:
Related Security Advisories:
Notification to the Requests repo including a fix in:
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-502"
],
"github_reviewed": true,
"github_reviewed_at": "2021-04-27T20:54:56Z",
"nvd_published_at": "2021-04-27T21:15:00Z",
"severity": "CRITICAL"
}