CVE-2025-50182
Vulnerability Summary
Timeline
Description
urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- v3.1•MEDIUM•Score: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Trends
Current EPSS score: 0.37%• Percentile: 30%
Techniques & Countermeasures
- CWE-601•URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Affected Systems
- chainguard•airflow-2
< 2.11.0-r5
- chainguard•airflow-2-bitnami-compat
< 2.11.0-r5
- chainguard•airflow-2-compat
< 2.11.0-r5
- chainguard•airflow-2-iamguarded-compat
< 2.11.0-r5
- chainguard•airflow-3
< 3.0.2-r2
- chainguard•airflow-3-bitnami-compat
< 3.0.2-r2
- chainguard•airflow-3-compat
< 3.0.2-r2
- chainguard•airflow-3-iamguarded-compat
< 3.0.2-r2
- chainguard•airflow-core-2
< 2.11.0-r3
- chainguard•airflow-core-2-compat
< 2.11.0-r3
- chainguard•airflow-core-2-oci-entrypoint
< 2.11.0-r3
- chainguard•ansible-operator
< 0
- chainguard•ansible-operator-compat
< 0
- chainguard•apache-beam-python-3.11-sdk
< 2.65.0-r2
- chainguard•az
< 2.74.0-r3
- chainguard•az-iamguarded-compat
< 2.74.0-r3
- chainguard•barman
< 3.14.1-r0
- chainguard•barman-cloudnative-pg
< 3.14.1-r0
- chainguard•confluent-docker-utils
< 0.0.162-r1
- chainguard•dask-gateway
< 2025.4.0-r1
- chainguard•dask-gateway-server
< 2025.4.0-r1
- chainguard•dask-kubernetes
< 2025.4.3-r4
- chainguard•datadog-agent-fips-7.71-core-integrations
< 7.71.2-r19
- chainguard•emissary
< 3.10.0-r6
- chainguard•emissary-apiext
< 3.10.0-r6
- chainguard•emissary-oci-entrypoint
< 3.10.0-r6
- chainguard•ggshield
< 1.43.0-r0
- chainguard•jupyter-base-notebook
< 7.4.3-r2
- chainguard•jupyter-docker-base
all
- chainguard•jupyter-docker-stacks
all | < 7.3.2-r1
- chainguard•jwt-tool
< 2.3.0-r2
- chainguard•k8s-sidecar
< 1.30.5-r0
- chainguard•katib-earlystopping
< 0.19.0-r3 | < 0.19.0-r0
- chainguard•kserve
< 0.16.0-r6
- chainguard•kserve-agent
< 0.16.0-r6
- chainguard•kserve-agent-compat
< 0.16.0-r6
- chainguard•kserve-manager
< 0.16.0-r6
- chainguard•kserve-manager-compat
< 0.16.0-r6
- chainguard•kserve-qpext
< 0.16.0-r6
- chainguard•kserve-qpext-compat
< 0.16.0-r6
- chainguard•kserve-router
< 0.16.0-r6
- chainguard•kserve-router-compat
< 0.16.0-r6
- chainguard•kserve-storage-controller
< 0.16.0-r6
- chainguard•kubeflow-jupyter-web-app
< 1.10.0-r5
- chainguard•kubeflow-pipelines
< 2.5.0-r4
- chainguard•kubeflow-pipelines-apiserver
< 2.5.0-r4
- chainguard•kubeflow-pipelines-cache_server
< 2.5.0-r4
- chainguard•kubeflow-pipelines-cache-deployer
< 2.5.0-r4
- chainguard•kubeflow-pipelines-cache-deployer-compat
< 2.5.0-r4
- chainguard•kubeflow-pipelines-frontend
< 2.5.0-r4
Showing first 50 affected entries in server-rendered view.
References (9)
- https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5
- https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f
- https://github.com/urllib3/urllib3/releases/tag/2.5.0
- https://nvd.nist.gov/vuln/detail/CVE-2025-50182
- https://github.com/urllib3/urllib3
- https://pypi.org/project/urllib3
- https://github.com/advisories/GHSA-48p4-8xcf-vxj5
- https://security-tracker.debian.org/tracker/CVE-2025-50182
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/50xxx/CVE-2025-50182.json