CVE-2025-4435

Deferred
Published: 03 Jun 2025, 12:59
Last modified:21 Apr 2026, 20:16

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.54% LOW
1% probability +0.46%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jun 2025, 12:59
Published
Vulnerability first disclosed
21 Apr 2026, 20:16
Last Modified
Vulnerability information updated

Description

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.54% Percentile: 68%

Techniques & Countermeasures

  • CWE-682Incorrect Calculation

    The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Affected Systems

  • python software foundationcpython

    < 3.9.23 | ≥ 3.10.0, < 3.10.18 | < 3.10.18 | ≥ 3.11.0, < 3.11.13 | ≥ 3.12.0, < 3.12.11 | ≥ 3.13.0, < 3.13.4 | ≥ 3.14.0a1, < 3.14.0b3

References (11)