cbcvebase.
CVE-2025-8194
published 2025-07-28

CVE-2025-8194: There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.61%
45.3th percentile
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

Affected

13 ranges
VendorProductVersion rangeFixed in
debianpypy3< python3.13 3.13.6-1 (forky)python3.13 3.13.6-1 (forky)
debianpython2.7< python3.13 3.13.6-1 (forky)python3.13 3.13.6-1 (forky)
debianpython3.11< python3.13 3.13.6-1 (forky)python3.13 3.13.6-1 (forky)
debianpython3.13< python3.13 3.13.6-1 (forky)python3.13 3.13.6-1 (forky)
debianpython3.9< python3.13 3.13.6-1 (forky)python3.13 3.13.6-1 (forky)
msrcazl3_python3_3.12.9-4_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0
msrccbl2_python3_3.9.19-14_on_cbl_mariner_2.0
python_software_foundationcpython< 3.10.193.10.19
python_software_foundationcpython>= 3.11.0 < 3.11.143.11.14
python_software_foundationcpython>= 3.12.0 < 3.12.123.12.12
python_software_foundationcpython>= 3.13.0 < 3.13.63.13.6
python_software_foundationcpython>= 3.14.0a1 < 3.14.0rc23.14.0rc2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle6.7HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.