CVE-2025-6075: Python

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

Affected products

  • Python Python: before 3.9.0 (fixed in 3.9.0); from 3.13.1, before 3.13.11 (fixed in 3.13.11); from 3.14.0, before 3.14.1 (fixed in 3.14.1); version 3.15.0 only

Published 2025-10-31. Last modified 2026-10-07.