How CVE-2025-50181 exposed a urllib3 dependency trap and forced a production migration from the legacy Elasticsearch client to OpenSearch.