CVE-2025-4435

Aliases:DEBIAN-CVE-2025-4435CGA-3xwx-5fgx-c58mCGA-gch4-rp2h-27fv
Deferred
Published: 03 Jun 2025, 12:59
Last modified:31 Jul 2026, 14:02

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.59% LOW
1% probability +0.51%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Jun 2025, 12:59
Published
Vulnerability first disclosed
31 Jul 2026, 14:02
Last Modified
Vulnerability information updated

Description

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.59% Percentile: 47%

Techniques & Countermeasures

  • CWE-682Incorrect Calculation

    The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Affected Systems

  • chainguardpython-3.13

    < 3.13.4-r0

  • wolfipython-3.13

    < 3.13.4-r0

  • debianpypy3

    all | < 7.3.20+dfsg-2

  • debianpython3.13

    < 3.13.4-1 | < 3.13.4-1

  • python software foundationcpython

    < 3.10.18 | < 3.9.23 | ≥ 3.10.0, < 3.10.18 | ≥ 3.11.0, < 3.11.13 | ≥ 3.12.0, < 3.12.11 | ≥ 3.13.0, < 3.13.4 | ≥ 3.14.0a1, < 3.14.0b3

References (15)