Back Linuxsecurity Debian: python-urllib3 Critical Denial of Service CVE-2025-50181 DLA-4421
CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager instantiation. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level remained vulnerable. CVE-2025-66418 The number of links in the decompression chain was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps which could lead to denial of service. For Debian 11 bullseye, these problems have been fixed in version 1.26.5-1~exp1+deb11u2. We recommend that you upgrade your python-urllib3 packages. For the detailed security status of python-urllib3 please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
CVE-2025-50181 Redirects were not disabled when retries are disabled on PoolManager instantiation. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level remained vulnerable. CVE-2025-66418 The number of links in the decompression chain was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps which could lead to denial of service. For Debian 11 bullseye, these problems have been fixed in version 1.26.5-1~exp1+deb11u2. We recommend that you upgrade your python-urllib3 packages. For the detailed security status of python-urllib3 please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
