CVE-2025-13462

Python vulnerabilities

Description

A flaw was found in the `tarfile` module of cpython. This vulnerability allows a remote attacker to craft a malicious tar archive that, when processed, could be misinterpreted by the `tarfile` module. This misinterpretation occurs because the module incorrectly applies normalization of `AREGTYPE` blocks to `DIRTYPE` during the processing of multi-block members, such as `GNUTYPE_LONGNAME` or `GNUTYPE_LONGLINK`. The consequence is that the `tarfile` module may process the archive differently than intended, potentially leading to unexpected file system changes or data integrity issues.

Metrics

Severity
low
no public PoC known
3.3
Source: nvd-v3
5.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-06 11:48 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    ubuntu / python2.7bionic

  • linux

    ubuntu / python2.7focal

  • linux

    ubuntu / python2.7jammy

  • linux

    ubuntu / python2.7trusty

  • linux

    ubuntu / python2.7xenial

  • linux

    ubuntu / python3.10jammy

  • linux

    ubuntu / python3.11jammy

  • linux

    ubuntu / python3.12noble

  • linux

    ubuntu / python3.14resolute

  • linux

    ubuntu / python3.4trusty

  • linux

    ubuntu / python3.5trusty

  • linux

    ubuntu / python3.5xenial

  • linux

    ubuntu / python3.6bionic

  • linux

    ubuntu / python3.7bionic

  • linux

    ubuntu / python3.8bionic

  • linux

    ubuntu / python3.8focal

  • linux

    ubuntu / python3.9focal

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • bitnami

    python-min3.6.0

  • bitnami

    python-min3.7.0

  • bitnami

    python-min3.8.0

  • bitnami

    python-min3.9.0

  • python

    python3.14.0 – 3.14.4

  • python

    python3.13.13

  • python

    python

  • python-markdown

    markdown

References & sources

Linked CVEs

IDCVE-2025-13462
Python vulnerabilities — CVE-2025-13462 | NEOSEC Intel