{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2025/cve-2025-50181-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T14:41:44Z",
      "generator": {
        "date": "2026-07-28T14:41:44Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-50181-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2025-06-19T01:15:00Z",
      "revision_history": [
        {
          "date": "2025-06-19T01:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T01:34:18Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-28T14:41:44Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2025-50181"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.el7.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.el7.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.el7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/python3-pip@9.0.3-8.el7?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-pip@9.0.3-8.el7.tuxcare.els1?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
                "product": {
                  "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
                  "product_id": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-pip@9.0.3-8.el7.tuxcare.els2?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-pip-0:9.0.3-8.el7.noarch as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch"
        },
        "product_reference": "python3-pip-0:9.0.3-8.el7.noarch",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-50181",
      "cwe": {
        "id": "CWE-601",
        "name": "URL Redirection to Untrusted Site ('Open Redirect')"
      },
      "notes": [
        {
          "category": "description",
          "text": "urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch",
          "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
          "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-50181"
        },
        {
          "category": "external",
          "summary": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857",
          "url": "https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857"
        },
        {
          "category": "external",
          "summary": "https://github.com/urllib3/urllib3/releases/tag/2.5.0",
          "url": "https://github.com/urllib3/urllib3/releases/tag/2.5.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v",
          "url": "https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"
        }
      ],
      "release_date": "2025-06-19T01:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T12:32:48.658204Z",
          "details": "Deprioritize this issue because it only manifests when an application directly uses urllib3.PoolManager and attempts to disable redirects via the retries parameter—a non-default pattern—while common higher-level clients (e.g., requests, botocore) are not affected by default. The flaw is limited to redirect control logic with no code execution or privilege escalation, low confidentiality and integrity impact, and no availability impact. Exploitation further depends on application behavior that makes outbound requests to attacker-controlled URLs and involves user interaction, making practical risk low in typical server/VM deployments.",
          "product_ids": [
            "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CentOS-7:python3-pip-0:9.0.3-8.el7.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els1.noarch",
            "CentOS-7:python3-pip-0:9.0.3-8.el7.tuxcare.els2.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}