PyPI: certifi

CVE-2024-39689

Safety vulnerability ID: SFTY-20240705-75966

Safety legacy ID: pyup.io-72083

Certifi affected versions recognized root certificates from GLOBALTRUST. Certifi patch removes these root certificates from the root store. These certificates are being removed pursuant to an investigation that identified "long-running and unresolved compliance issues" and are also in the process of being removed from Mozilla's trust store.

Created at: Nov 5, 2025Updated at: Nov 5, 2025

Overview

Certifi removes GLOBALTRUST root certificate

Advisory

Certifi affected versions recognized root certificates from GLOBALTRUST. Certifi patch removes these root certificates from the root store. These certificates are being removed pursuant to an investigation that identified "long-running and unresolved compliance issues" and are also in the process of being removed from Mozilla's trust store.

Affected Package

Affecting certifi package, versions
>=2021.05.30,<2024.07.04

Also affects

---

How to Fix

Upgrade
certifi
to
2024.7.4
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more