Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-4138

19
FAUCET Score

CVE-2025-4138 is a path traversal vulnerability affecting the Python tarfile module when extracting untrusted archives using specific filter parameters. This flaw allows attackers to bypass extraction filters, enabling symlink targets to point outside the intended destination directory and modify file metadata. Rated 7.5 HIGH on the CVSS scale, this vulnerability can be exploited remotely with low attack complexity, potentially leading to high confidentiality impact. There is currently no evidence of active exploitation, and no public exploit code is available, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.10.18CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.12.0, < 3.12.11CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.13.0, < 3.13.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.15%
Probability of exploitation in next 30 days
EPSS Percentile
63.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0115 is in the 42nd percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (49)

microsoftpatch availablevia msrc
Product: 19533-16823Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 19681-17086Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 17667-17084
microsoftpatch availablevia msrc
Product: 17604-17084Fixed in: 3.12.9-2
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-14 on CBL Mariner 2.0Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-13 on CBL Mariner 2.0Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: azl3 tensorflow 2.16.1-9 on Azure Linux 3.0
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-1 on Azure Linux 3.0Fixed in: 3.12.9-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: python3-0:3.6.8-47.el8_6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-OnFixed in: python3-0:3.6.8-51.el8_8.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: python3-0:3.6.8-51.el8_8.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: python3-0:3.6.8-51.el8_8.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9-0:3.9.21-2.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11-0:3.11.11-2.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12-0:3.12.9-1.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: python3.12-0:3.12.1-4.el9_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: python3.9-0:3.9.18-3.el9_4.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: python3.11-0:3.11.7-1.el9_4.8
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-operator-bundle:7.13.5-25
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-management-console-rhel8:1.36.0-9
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-operator-bundle:1.36.0-12
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-rhel8-operator:1.36.0-18
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7
View patch
redhatpatch availablevia redhat_api
Product: cert-manager operator for Red Hat OpenShift 1.16Fixed in: cert-manager/jetstack-cert-manager-rhel9:sha256:df852ad92734bc087e213e6c7075daf6d7010db4ab72919649736804e295a6a2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.36-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12-0:3.12.9-2.el10_0.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11-0:3.11.13-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12-0:3.12.11-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-70.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: python3-0:3.6.8-47.el8_6.8
View patch

Vendor Advisories (2)

microsoft2025-Jun/CVE-2025-4138Important

Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

Jun 10, 2025
redhatCVE-2025-4138Important

cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

Jun 3, 2025

References

gist.github.com / sethmlarson/52398e33eff261329a0180ac1d54f42f
github.com / python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da
github.com / python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9
github.com / python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a
github.com / python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e
github.com / python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a
github.com / python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a
github.com / python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01
github.com / python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1
github.com / python/cpython/issues/135034
github.com / python/cpython/pull/135037
mail.python.org / archives/list/[email protected]/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG