Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-4516

20
FAUCET Score

CVE-2025-4516 is a medium-severity vulnerability affecting CPython when using bytes.decode("unicode_escape", error="ignore|replace"). It allows for a denial of service (VA:H) with a CVSS score of 5.9, but only impacts systems not using the "unicode_escape" encoding or an error handler. The attack vector is local (AV:L) with high attack complexity (AC:H), and there are no known public exploits, Metasploit modules, or Nuclei templates available. While there is limited community discussion and media coverage, the vulnerability is not currently on CISA's KEV or Hot List.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.10.18CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.12.0, < 3.12.11CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.13.0, < 3.13.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.9MEDIUM

CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 4th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (34)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-2 on Azure Linux 3.0Fixed in: 3.12.9-2
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-14 on CBL Mariner 2.0Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-13 on CBL Mariner 2.0Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 19533-16823Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 19681-17086Fixed in: 3.9.19-14
microsoftpatch availablevia msrc
Product: 19601-17084Fixed in: 3.12.9-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8100020251126112422.d47b87a4
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-aws-nvidia-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-azure-amd-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-azure-nvidia-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-gcp-nvidia-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-nvidia-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/granite-3.1-8b-lab-v2.1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/granite-3.1-8b-starter-v2.1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/instructlab-amd-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/instructlab-nvidia-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/modelcar-granite-3-1-8b-lab-v2-1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/modelcar-granite-3-1-8b-starter-v2-1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-intel-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python36:3.6/python36
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-amd-rhel9

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2025-4516Moderate

cpython: python: CPython DecodeError Handling Vulnerability

May 15, 2025
microsoft2025-May/CVE-2025-4516Moderate

Use-after-free in "unicode_escape" decoder with error handler

May 13, 2025

References

openwall.com / lists/oss-security/2025/05/16/4
openwall.com / lists/oss-security/2025/05/19/1
github.com / python/cpython/commit/4398b788ffc1f954a2c552da285477d42a571292
github.com / python/cpython/commit/6279eb8c076d89d3739a6edb393e43c7929b429d
github.com / python/cpython/commit/69b4387f78f413e8c47572a85b3478c47eba8142
github.com / python/cpython/commit/73b3040f592436385007918887b7e2132aa8431f
github.com / python/cpython/commit/8d35fd1b34935221aff23a1ab69a429dd156be77
github.com / python/cpython/commit/9f69a58623bd01349a18ba0c7a9cb1dad6a51e8e
github.com / python/cpython/commit/ab9893c40609935e0d40a6d2a7307ea51aec598b
github.com / python/cpython/issues/133767
github.com / python/cpython/pull/129648
mail.python.org / archives/list/[email protected]/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74