It was discovered that the urllib3 Python HTTP library didn't sanitise some cross-origin redirects, which could result in information disclosure. For the stable distribution (trixie), this problem has been fixed in version 2.3.0-3+deb13u2.

Source: Debian python-urllib3 Important Cross-Origin Info Disclosure Fix DSA-6363-1