CVE-2025-4435: Python Software Foundation Cpython
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
Affected products
- Python Software Foundation Cpython: before 3.9.23 (fixed in 3.9.23); from 3.10.0, before 3.10.18 (fixed in 3.10.18); from 3.11.0, before 3.11.13 (fixed in 3.11.13); from 3.12.0, before 3.12.11 (fixed in 3.12.11); from 3.13.0, before 3.13.4 (fixed in 3.13.4); from 3.14.0a1, before 3.14.0b3 (fixed in 3.14.0b3)
Published 2025-06-03. Last modified 2026-07-31.