More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2373800 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://nvd.nist.gov/vuln/detail/CVE-2025-50182 explicitly mentions: > Starting in version 2.2.0 and prior to 2.5.0... $ repoquery -q --releasever=42 --repo=fedora --provides python3-pip | grep urllib bundled(python3dist(urllib3)) = 1.26.20