Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Per https://www.cve.org/CVERecord?id=CVE-2025-66471, this is fixed in 2.6.0 and later. Fedora 43 has 2.3.0, so it is affected. The fix is probably not straightforward to backport. An update may be possible, but includes new nontrivial dependencies. See https://src.fedoraproject.org/rpms/python-urllib3/pull-request/49 for discussion.