Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-13462

17
FAUCET Score

CVE-2025-13462 identifies a vulnerability in the `tarfile` module where crafted tar archives can be misinterpreted due to incorrect normalization of block types, potentially leading to unexpected file system behavior. Rated with a CVSS 2.0 LOW score and a FAUCET Risk Score of 24.0/100, exploitation requires local access and high attack complexity, with a low impact on integrity and no impact on confidentiality or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.14.0, < 3.14.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
< 3.13.13CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
3.15.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
3.15.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
6.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 5th percentile among its peer group of 61 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 21492-17084Fixed in: 3.12.9-13
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-13 on Azure Linux 3.0Fixed in: 3.12.9-13
microsoftpatch availablevia msrc
Product: 21379-17084Fixed in: 3.12.9-12
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-11 on Azure Linux 3.0Fixed in: 3.12.9-12
ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026
microsoft2026-Mar/CVE-2025-13462Low

tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

Mar 10, 2026

References

github.com / python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8ab
Patch
github.com / python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114
Patch
github.com / python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017
Patch
github.com / python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406
Patch
github.com / python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7
Patch
github.com / python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084
Patch
github.com / python/cpython/issues/141707
Issue Tracking
github.com / python/cpython/pull/143934
Issue TrackingPatch
mail.python.org / archives/list/[email protected]/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE
Mailing ListVendor Advisory