Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-12781

20
FAUCET Score

CVE-2025-12781 describes a data integrity vulnerability in the Python "base64" module, specifically affecting the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions. These functions incorrectly accept '+' and '/' characters even when an alternative base64 alphabet is specified, potentially leading to data integrity issues if an application relies on a strict alternative alphabet. Rated 5.3 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N), the vulnerability is network-exploitable with low attack complexity, but its impact is limited to data integrity (I:L). There is currently no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.10CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.14.0, < 3.14.1CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
< 3.13.10CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
3.15.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 26th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (27)

github_advisorypatch availablevia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.14
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python36:3.6/python36
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9/python39
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.14
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-aws-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-azure-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-gcp-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/code-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/pluginregistry-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-tech-preview/idea-rhel9

Vendor Advisories (1)

redhatCVE-2025-12781Moderate

cpython: base64.b64decode() always accepts "+/" characters, despite setting altchars

Jan 21, 2026

References

github.com / python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b
Patch
github.com / python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947
Patch
github.com / python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5
Patch
github.com / python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76
Patch
github.com / python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5
Patch
github.com / python/cpython/issues/125346
ExploitIssue Tracking
github.com / python/cpython/pull/141128
Issue TrackingPatch
mail.python.org / archives/list/[email protected]/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6
Mailing ListVendor Advisory