- Description
- urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- urllib3
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-601
- Hype score
- Not currently trending
๐ Lambda Watchdog detected that CVE-2025-50181 is no longer present in latest AWS Lambda base image scans. https://t.co/D1NCs5ZevN #AWS #Lambda #Security #CVE #DevOps #SecOps
@LambdaWatchdog
10 Jan 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ Fedora 41 Security Alert! ๐จ CVE-2025-50181 affects python-pip. The bundled urllib3 didn't disable redirects when retries were offโa serious security misconfiguration. Read more: ๐ https://t.co/Z6Z7FXeZFe #Security https://t.co/hzy4d97yCs
@Cezar_H_Linux
28 Sept 2025
50 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Fedora 42: python-pip 2025-6d50efcd0c https://t.co/Hadwn7fdSY Security fix for the bundled urllib3 for CVE-2025-50181 #cybersecurity #cyber #security #hackers #cyberattack #databreach #incidentresponse #China
@zeeshankghouri
22 Sept 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ Urgent #Security Update for #SUSE & #openSUSE users! CVE-2025-50181 affects python-urllib3 (CVSS 6.0), risking data exposure. Affects: SLE 15 SP6/SP7, Leap 15.3, MicroOS 5.1-5.5. Read more: ๐ https://t.co/xTEf7dVWbb https://t.co/dUJrw31dBr
@Cezar_H_Linux
27 Aug 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: #Fedora41โs PyPy update fixes: CVE-2025-47273 (Path traversal) CVE-2024-47081 (.netrc leak) CVE-2025-50181 (urllib3 redirects) Update: sudo dnf upgrade --advisory FEDORA-2025-9b8da6ad7e Read more:๐ https://t.co/57SitW9GHj #DevSecOps https://t.co/65THK56L34
@Cezar_H_Linux
20 Jul 2025
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐ฅ Breaking: #Ubuntuโs urllib3 has a CRITICAL flaw (CVE-2025-50181) leaking passwords/API keys! โ Patch: sudo apt update && sudo apt upgrade python3-urllib3 #LinuxSecurity #DevOps https://t.co/FKM83XISkf
@Cezar_H_Linux
26 Jun 2025
28 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:python:urllib3:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C2B2EF-1774-47F0-9480-F5CE26947B78",
"versionEndExcluding": "2.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]