CVE-2025-50181(python / urllib3)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • urllib3

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
urllib3

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-25: 209-25
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CowNinja@JJ_Bloom

    Try this once on your box: check which urllib3 actually resolved, then pin 2.5.0 or higher and re-run pip-audit until it is clean. NVD write-up for CVE-2025-50181: https://nvd.nist.gov/vuln/detail/CVE-2025-50181

    0001025
    4.0K followersView on X
  • HackerNoon | Learn Any Technology@hackernoon

    How CVE-2025-50181 exposed a urllib3 dependency trap and forced a production migration from the legacy Elasticsearch client to OpenSearch. #elasticsearch #django...Show more https://t.co/KG9WjzsMTe

    100001.2K
    94.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonurllib3---

Explore more