CVE-2025-4516: Python Software Foundation Cpython
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.
Affected products
- Python Software Foundation Cpython: before 3.9.23 (fixed in 3.9.23); from 3.10.0, before 3.10.18 (fixed in 3.10.18); from 3.11.0, before 3.11.13 (fixed in 3.11.13); from 3.12.0, before 3.12.11 (fixed in 3.12.11); from 3.13.0, before 3.13.4 (fixed in 3.13.4); from 3.14.0a1, before 3.14.0b2 (fixed in 3.14.0b2)
Published 2025-05-15. Last modified 2026-07-31.