CVE-2025-50182Medium· 5.3▾ SunlitA flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can en…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.4%
Last analysed / modified upstream
A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This vulnerability stems from a failure to constrain the redirect target.
urllib3: urllib3 does not control redirects in browsers and Node.js — rated Moderate by Red Hat. Released 2025-06-19, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. https://access.redhat.com/errata/RHSA-2026:62115 The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. https://access.redhat.com/errata/RHSA-2026:3406
Workarounds / mitigations:
Affected packages:
urllib3 >= 2.2.0, < 2.5.0Patched in:
urllib3 2.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45409Medium· 5.3python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409)
CVE-2026-80948Medium· 5.5kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)
CVE-2026-80936Medium· 5.5kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop (CVE-2026-80936)
CVE-2026-80947High· 7.0kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)
CVE-2026-80980Medium· 5.5kernel: net/smc: stop killed, freed and out_of_sync sharing a byte (CVE-2026-80980)
CVE-2026-80981High· 7.0kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)