CVE-2025-50181

CWE-601Open Redirect15 documents10 sources
Severity
6.1MEDIUM
EPSS
0.0%
top 92.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateOct 15

Description

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages6 packages

NVDpython/urllib3< 2.5.0
Debianpython-urllib3< 1.26.5-1~exp1+deb11u2+3
Ubuntupython-urllib3< 1.26.5-1~exp1ubuntu0.3+4
PyPIurllib3< 2.5.0
CVEListV5urllib3/urllib3< 2.5.0

Patches

🔴Vulnerability Details

6
OSV
python-pip vulnerability2025-06-26
OSV
python-urllib3 vulnerabilities2025-06-25
CVEList
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation2025-06-19
OSV
CVE-2025-50181: urllib3 is a user-friendly HTTP client library for Python2025-06-19
GHSA
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation2025-06-18

📋Vendor Advisories

7
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Porting (urllib3) — CVE-2025-501812025-10-15
Ubuntu
pip vulnerability2025-06-26
Ubuntu
urllib3 vulnerabilities2025-06-25
Red Hat
urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation2025-06-19
Microsoft
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation2025-06-10

💬Community

1
Bugzilla
CVE-2025-50181 pypy: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation [fedora-42]2025-07-25
CVE-2025-50181 (MEDIUM CVSS 6.1) | urllib3 is a user-friendly HTTP cli | cvebase.io