<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:30:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09791</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09791</link>
      <description>bdu:2025-09791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09791</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-50181</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-50181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-urllib3, Alpaquita:stream: py3-urllib3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-urllib3, Alpaquita:stream: py3-urllib3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-50181</guid>
    </item>
    <item>
      <title>BREW-abi3audit-CVE-2025-50181 — urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation</title>
      <link>https://cve.radiocsirt.org/vuln/brew-abi3audit-cve-2025-50181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: abi3audit&lt;/p&gt;
&lt;p&gt;urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:&lt;/p&gt;
&lt;p&gt;```python
resp = urllib3.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;, redirect=False)
print(resp.status)
# 302
```&lt;/p&gt;
&lt;p&gt;However, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:&lt;/p&gt;
&lt;p&gt;```python
import urllib3&lt;/p&gt;
&lt;p&gt;http = urllib3.PoolManager(retries=0)  # should raise MaxRetryError on redirect
http = urllib3.PoolManager(retries=urllib3.Retry(redirect=0))  # equivalent to the above
http = urllib3.PoolManager(retries=False)  # should return the first response&lt;/p&gt;
&lt;p&gt;resp = http.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;However, the `retries` parameter is currently ignored, which means all the above examples don&amp;#39;t disable redirects.&lt;/p&gt;
&lt;p&gt;## Affected usages&lt;/p&gt;
&lt;p&gt;Passing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.&lt;/p&gt;
&lt;p&gt;By default, requests and botocore users are not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Redirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;You can remediate this vulnerability with the following steps:&lt;/p&gt;
&lt;p&gt;* Upgrade to a patched version of urllib3. If your organization would benefit from the continued supp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: abi3audit&lt;/p&gt;
&lt;p&gt;urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:&lt;/p&gt;
&lt;p&gt;```python
resp = urllib3.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;, redirect=False)
print(resp.status)
# 302
```&lt;/p&gt;
&lt;p&gt;However, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:&lt;/p&gt;
&lt;p&gt;```python
import urllib3&lt;/p&gt;
&lt;p&gt;http = urllib3.PoolManager(retries=0)  # should raise MaxRetryError on redirect
http = urllib3.PoolManager(retries=urllib3.Retry(redirect=0))  # equivalent to the above
http = urllib3.PoolManager(retries=False)  # should return the first response&lt;/p&gt;
&lt;p&gt;resp = http.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;However, the `retries` parameter is currently ignored, which means all the above examples don&amp;#39;t disable redirects.&lt;/p&gt;
&lt;p&gt;## Affected usages&lt;/p&gt;
&lt;p&gt;Passing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.&lt;/p&gt;
&lt;p&gt;By default, requests and botocore users are not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Redirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;You can remediate this vulnerability with the following steps:&lt;/p&gt;
&lt;p&gt;* Upgrade to a patched version of urllib3. If your organization would benefit from the continued supp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-abi3audit-cve-2025-50181</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>EUVD-2026-264251</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264251</link>
      <description>EUVD-2026-264251</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264251</guid>
    </item>
    <item>
      <title>fkie_cve-2025-50181</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-50181</link>
      <description>&lt;p&gt;urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-50181</guid>
    </item>
    <item>
      <title>GHSA-pq67-6m6q-mj2v — urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pq67-6m6q-mj2v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:&lt;/p&gt;
&lt;p&gt;```python
resp = urllib3.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;, redirect=False)
print(resp.status)
# 302
```&lt;/p&gt;
&lt;p&gt;However, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:&lt;/p&gt;
&lt;p&gt;```python
import urllib3&lt;/p&gt;
&lt;p&gt;http = urllib3.PoolManager(retries=0)  # should raise MaxRetryError on redirect
http = urllib3.PoolManager(retries=urllib3.Retry(redirect=0))  # equivalent to the above
http = urllib3.PoolManager(retries=False)  # should return the first response&lt;/p&gt;
&lt;p&gt;resp = http.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;However, the `retries` parameter is currently ignored, which means all the above examples don&amp;#39;t disable redirects.&lt;/p&gt;
&lt;p&gt;## Affected usages&lt;/p&gt;
&lt;p&gt;Passing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.&lt;/p&gt;
&lt;p&gt;By default, requests and botocore users are not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Redirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;You can remediate this vulnerability with the following steps:&lt;/p&gt;
&lt;p&gt;* Upgrade to a patched version of urllib3. If your organization would benefit from the continued supp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:&lt;/p&gt;
&lt;p&gt;```python
resp = urllib3.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;, redirect=False)
print(resp.status)
# 302
```&lt;/p&gt;
&lt;p&gt;However, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:&lt;/p&gt;
&lt;p&gt;```python
import urllib3&lt;/p&gt;
&lt;p&gt;http = urllib3.PoolManager(retries=0)  # should raise MaxRetryError on redirect
http = urllib3.PoolManager(retries=urllib3.Retry(redirect=0))  # equivalent to the above
http = urllib3.PoolManager(retries=False)  # should return the first response&lt;/p&gt;
&lt;p&gt;resp = http.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;However, the `retries` parameter is currently ignored, which means all the above examples don&amp;#39;t disable redirects.&lt;/p&gt;
&lt;p&gt;## Affected usages&lt;/p&gt;
&lt;p&gt;Passing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.&lt;/p&gt;
&lt;p&gt;By default, requests and botocore users are not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Redirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;You can remediate this vulnerability with the following steps:&lt;/p&gt;
&lt;p&gt;* Upgrade to a patched version of urllib3. If your organization would benefit from the continued supp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pq67-6m6q-mj2v</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-50181 — urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-50181</link>
      <description>msrc_CVE-2025-50181</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-50181</guid>
    </item>
    <item>
      <title>OESA-2025-1958 — python-urllib3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1958</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-urllib3, openEuler:24.03-LTS-SP2: python-urllib3, openEuler:20.03-LTS-SP4: python-urllib3, openEuler:22.03-LTS-SP3: python-urllib3, openEuler:22.03-LTS-SP4: python-urllib3, openEuler:24.03-LTS: python-urllib3&lt;/p&gt;
&lt;p&gt;HTTP library with thread-safe connection pooling, file post support, sanity friendly, and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.(CVE-2025-50181)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-urllib3, openEuler:24.03-LTS-SP2: python-urllib3, openEuler:20.03-LTS-SP4: python-urllib3, openEuler:22.03-LTS-SP3: python-urllib3, openEuler:22.03-LTS-SP4: python-urllib3, openEuler:24.03-LTS: python-urllib3&lt;/p&gt;
&lt;p&gt;HTTP library with thread-safe connection pooling, file post support, sanity friendly, and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.(CVE-2025-50181)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1958</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15283-1 — python311-urllib3-2.5.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15283-1</link>
      <description>&lt;p&gt;python311-urllib3-2.5.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-urllib3-2.5.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15283-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1999 — urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1999</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:&lt;/p&gt;
&lt;p&gt;```python
resp = urllib3.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;, redirect=False)
print(resp.status)
# 302
```&lt;/p&gt;
&lt;p&gt;However, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:&lt;/p&gt;
&lt;p&gt;```python
import urllib3&lt;/p&gt;
&lt;p&gt;http = urllib3.PoolManager(retries=0)  # should raise MaxRetryError on redirect
http = urllib3.PoolManager(retries=urllib3.Retry(redirect=0))  # equivalent to the above
http = urllib3.PoolManager(retries=False)  # should return the first response&lt;/p&gt;
&lt;p&gt;resp = http.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;However, the `retries` parameter is currently ignored, which means all the above examples don&amp;#39;t disable redirects.&lt;/p&gt;
&lt;p&gt;## Affected usages&lt;/p&gt;
&lt;p&gt;Passing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.&lt;/p&gt;
&lt;p&gt;By default, requests and botocore users are not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Redirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;You can remediate this vulnerability with the following steps:&lt;/p&gt;
&lt;p&gt;* Upgrade to a patched version of urllib3. If your organization would benefit from the continued supp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;urllib3 handles redirects and retries using the same mechanism, which is controlled by the `Retry` object. The most common way to disable redirects is at the request level, as follows:&lt;/p&gt;
&lt;p&gt;```python
resp = urllib3.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;, redirect=False)
print(resp.status)
# 302
```&lt;/p&gt;
&lt;p&gt;However, it is also possible to disable redirects, for all requests, by instantiating a `PoolManager` and specifying `retries` in a way that disable redirects:&lt;/p&gt;
&lt;p&gt;```python
import urllib3&lt;/p&gt;
&lt;p&gt;http = urllib3.PoolManager(retries=0)  # should raise MaxRetryError on redirect
http = urllib3.PoolManager(retries=urllib3.Retry(redirect=0))  # equivalent to the above
http = urllib3.PoolManager(retries=False)  # should return the first response&lt;/p&gt;
&lt;p&gt;resp = http.request(&amp;#34;GET&amp;#34;, &amp;#34;https://httpbin.org/redirect/1&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;However, the `retries` parameter is currently ignored, which means all the above examples don&amp;#39;t disable redirects.&lt;/p&gt;
&lt;p&gt;## Affected usages&lt;/p&gt;
&lt;p&gt;Passing `retries` on `PoolManager` instantiation to disable redirects or restrict their number.&lt;/p&gt;
&lt;p&gt;By default, requests and botocore users are not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Redirects are often used to exploit SSRF vulnerabilities. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;You can remediate this vulnerability with the following steps:&lt;/p&gt;
&lt;p&gt;* Upgrade to a patched version of urllib3. If your organization would benefit from the continued supp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1999</guid>
    </item>
    <item>
      <title>RHSA-2026:33154 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33154</link>
      <description>&lt;p&gt;pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools tar-fs: link following and path traversal via maliciously crafted tar file nanoid: nanoid mishandles non-integer values brace-expansion: juliangruber brace-expansion index.js expand redos lodash: prototype pollution in _.unset and _.omit functions golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation ceph: privilege escalation by unprivileged users in a ceph-fuse mounted CephFS tar-fs: tar-fs symlink validation bypass urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools tar-fs: link following and path traversal via maliciously crafted tar file nanoid: nanoid mishandles non-integer values brace-expansion: juliangruber brace-expansion index.js expand redos lodash: prototype pollution in _.unset and _.omit functions golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation ceph: privilege escalation by unprivileged users in a ceph-fuse mounted CephFS tar-fs: tar-fs symlink validation bypass urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33154</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02736-1 — Security update for python-urllib3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02736-1</link>
      <description>&lt;p&gt;Security update for python-urllib3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-urllib3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02736-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-50181</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-50181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-urllib3, Ubuntu:Pro:18.04:LTS: python-urllib3, Ubuntu:Pro:20.04:LTS: python-urllib3, Ubuntu:22.04:LTS: python-pip, Ubuntu:22.04:LTS: python-urllib3, Ubuntu:24.04:LTS: python-pip, Ubuntu:24.04:LTS: python-urllib3&lt;/p&gt;
&lt;p&gt;urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-urllib3, Ubuntu:Pro:18.04:LTS: python-urllib3, Ubuntu:Pro:20.04:LTS: python-urllib3, Ubuntu:22.04:LTS: python-pip, Ubuntu:22.04:LTS: python-urllib3, Ubuntu:24.04:LTS: python-pip, Ubuntu:24.04:LTS: python-urllib3&lt;/p&gt;
&lt;p&gt;urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-50181</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2154 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2154</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2154</guid>
    </item>
  </channel>
</rss>
