---
id: CVE-2025-50182
title: >-
  urllib3: urllib3 does not control redirects in browsers and Node.js
  (CVE-2025-50182)
summary: >-
  A flaw was found in urllib3. The library fails to properly validate redirect
  URLs, allowing an attacker to manipulate redirect chains when used in
  environments like Pyodide utilizing the JavaScript Fetch API. This lack of
  validation can en…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cvssSource: vendor
cwe: CWE-601
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - builds_for_red_hat_openshift
  - cert_manager_operator_for_red_hat_openshift
  - confidential_compute_attestation
  - custom_metric_autoscaler_operator_for_red_hat_openshift
  - migration_toolkit_for_virtualization
  - multiarch_tuning_operator
  - network_observability_operator
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_serverless
  - openshift_service_mesh 3
  - ai_inference_server
  - ansible_automation_platform 2
  - ceph_storage 6
  - ceph_storage 7
  - developer_hub
  - discovery 1
  - edge_manager_preview
  - enterprise_linux 10
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai
  - offline_knowledge_portal
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - quay 3
  - satellite 6
  - trusted_artifact_signer
  - ceph_storage 8.1
  - ceph_storage 9
patched:
  - ceph_storage 8.1
  - ceph_storage 9
published: '2025-06-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:17:00+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50182.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50182.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-50182'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2373800'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-50182'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-50182'
  - url: >-
      https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f
  - url: 'https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62115'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3406'
  - url: 'https://github.com/urllib3/urllib3'
  - url: 'https://github.com/urllib3/urllib3/releases/tag/2.5.0'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00393
epssPercentile: 0.30661
aliases:
  - GHSA-48p4-8xcf-vxj5
  - PYSEC-2026-1997
ecosystem: pip
ingestedAt: '2026-07-08T18:25:45.294Z'
---

## Overview

A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This 
vulnerability stems from a failure to constrain the redirect target.

## Vendor advisories

- **RHSA-2026:62115** · Red Hat · fixed in: Red Hat Ceph Storage 8.1 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62115)
- **RHSA-2026:3406** · Red Hat · fixed in: Red Hat Ceph Storage 9 · released 2026-02-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:3406)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Confidential Compute Attestation, Custom Metric Autoscaler operator for Red Hat Openshift, Migration Toolkit for Virtualization, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Migration Toolkit for Virtualization, Network Observability Operator, OpenShift Pipelines, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-50182.json)

**urllib3: urllib3 does not control redirects in browsers and Node.js** — rated Moderate by Red Hat. Released 2025-06-19, updated 2026-09-21.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Confidential Compute Attestation
- Custom Metric Autoscaler operator for Red Hat Openshift
- Migration Toolkit for Virtualization
- Multiarch Tuning Operator
- Network Observability Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 3
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Developer Hub
- Red Hat Discovery 1
- Red Hat Edge Manager preview
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Offline Knowledge Portal
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Quay 3
- Red Hat Satellite 6
- Red Hat Trusted Artifact Signer

Fixed:

- Red Hat Ceph Storage 8.1
- Red Hat Ceph Storage 9

No fix planned:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Migration Toolkit for Virtualization
- Network Observability Operator
- OpenShift Pipelines
- Red Hat Ansible Automation Platform 2
- Red Hat Developer Hub
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat Trusted Artifact Signer
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Confidential Compute Attestation
- Custom Metric Autoscaler operator for Red Hat Openshift
- Multiarch Tuning Operator
- OpenShift Lightspeed
- OpenShift Serverless
- OpenShift Service Mesh 3
- Red Hat AI Inference Server
- Red Hat Discovery 1
- Red Hat Edge Manager preview
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Offline Knowledge Portal
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Quay 3
- Red Hat Satellite 6
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7

Not affected:

- Red Hat Ceph Storage 8.1
- Red Hat Ceph Storage 9
- Red Hat build of Quarkus Native builder
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9

## Remediation

The container images provided by this update can be downloaded from the
Red Hat container registry at registry.redhat.io using the "podman pull" command. https://access.redhat.com/errata/RHSA-2026:62115
The container images provided by this update can be downloaded from the
Red Hat container registry at registry.redhat.io using the "podman pull" command. https://access.redhat.com/errata/RHSA-2026:3406

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-50182)

Affected packages:

- `urllib3 >= 2.2.0, < 2.5.0`

Patched in:

- `urllib3 2.5.0`

Source: https://osv.dev/vulnerability/GHSA-48p4-8xcf-vxj5
