Root has patched CVE-2018-25091 in the rootio-urllib3 package for Root:PyPI. Multiple fixed versions available.
{ "source": "Root", "distro_version": "", "distro": "pypi" }
"https://api.root.io/external/osv/ROOT-APP-PYPI-CVE-2018-25091.json"
true
[ "1.23+root.io.2" ]
"root.io.2"
1.0
"1.23"