
Try this once on your box: check which urllib3 actually resolved, then pin 2.5.0 or higher and re-run pip-audit until it is clean. NVD write-up for CVE-2025-50181: https://nvd.nist.gov/vuln/detail/CVE-2025-50181
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

Try this once on your box: check which urllib3 actually resolved, then pin 2.5.0 or higher and re-run pip-audit until it is clean. NVD write-up for CVE-2025-50181: https://nvd.nist.gov/vuln/detail/CVE-2025-50181

How CVE-2025-50181 exposed a urllib3 dependency trap and forced a production migration from the legacy Elasticsearch client to OpenSearch. #elasticsearch #django...Show more https://t.co/KG9WjzsMTe
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | python | urllib3 | - | - | - |