CVE-2025-50181
Public on 2025-06-19
Modified on 2025-06-20
Description
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | python-pip | Pending Fix | ||
Amazon Linux 2023 | python-pip | Pending Fix | ||
Amazon Linux 1 | python-urllib3 | No Fix Planned | ||
Amazon Linux 2 - Core | python-urllib3 | Pending Fix | ||
Amazon Linux 2023 | python-urllib3 | Pending Fix | ||
Amazon Linux 2 - Core | python3-urllib3 | Pending Fix | ||
Amazon Linux 2023 | python3.11-pip | Pending Fix | ||
Amazon Linux 2023 | python3.12-pip | Pending Fix |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 5.3 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
NVD | CVSSv3 | 5.3 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |