The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
CVE-2025-13462
Score 9.8 from GitHub Security Advisory (severity: LOW) published 2026-03-12. NVD baseline CVSS 3.3; sources differ by 6.5.
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 3.3
- EG Score
- 9.8(medium)
- EG Risk
- 44(Track)EG Risk 44/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation0% × 40%Automatability0% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 6%
- KEV
- Not listed
Published
March 12, 2026
Last Modified
August 13, 2026
Advisory Details (9)
Auto-updated Jun 5, 2026Mailman 3 [CVE-2025-13462]: tarfile: Skip DIRTYPE normalization during GNU long name and link handling - Security-announce - python.org
https://mail.python.org/archives/list/[email protected]/thread/EOMI5I66ZMKQ2INNFT6T7IAIKUGPZYIE/gh-141707: Skip TarInfo DIRTYPE normalization during GNU long name handling
Fix merged in python/cpython PR #143934 on 2026-03-11 — awaiting tagged release
https://github.com/python/cpython/pull/143934Incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined · Issue #141707 · python/cpython · GitHub
https://github.com/python/cpython/issues/141707commit d10950739a78 (python/cpython)
Fix landed in python/cpython commit d10950739a78 — awaiting tagged release
https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084commit ae99fe3a33b4 (python/cpython)
Fix landed in python/cpython commit ae99fe3a33b4 — awaiting tagged release
https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7commit 9a23b753552a (python/cpython)
Fix landed in python/cpython commit 9a23b753552a — awaiting tagged release
https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406commit 7ad3093d76a7 (python/cpython)
Fix landed in python/cpython commit 7ad3093d76a7 — awaiting tagged release
https://github.com/python/cpython/commit/7ad3093d76a748af55bdb1d2e8aad3638163b017commit 72dde1016493 (python/cpython)
Fix landed in python/cpython commit 72dde1016493 — awaiting tagged release
https://github.com/python/cpython/commit/72dde1016493c52abe857fc4a7bf6c40138b4114commit 42d754e34c06 (python/cpython)
Fix landed in python/cpython commit 42d754e34c06 — awaiting tagged release
https://github.com/python/cpython/commit/42d754e34c06e57ad6b8e7f92f32af679912d8abVendor Advisories for CVE-2025-13462(6)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- CVE-2025-13462Microsoft Security Response Center (MSRC)Low
tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
- RHSA-2026:11324Red Hat Product SecurityLow
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
- RHSA-2026:10118Red Hat Product SecurityMedium
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
- RHSA-2026:7661Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
- RHSA-2026:7443Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
- GHSA-9qpv-486p-2v4hGitHub Security AdvisoriesLow
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even...
Patch Availability(4)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | python3-11-main-3.11.15-4.2.hum1 | 2026-04-28 | redhat |
| redhat | python3-12-main-3.12.13-3.1.hum1 | 2026-04-23 | redhat |
| redhat | python3-14-main-3.14.4-1.hum1 | 2026-04-11 | redhat |
| redhat | python3-13-main-3.13.13-1.hum1 | 2026-04-10 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(6 across 4 ecosystems)
Debian:11(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| python2.7 | 2.7.18-10 ... 2.7.18-9 (10 versions) | — | — |
| python3.9 | 3.9.2-1 ... 3.9.2-1+deb11u6 (7 versions) | 3.9.2-1+deb11u7 | — |
Debian:14(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| python3.13 | 3.13.11-1 ... 3.13.9-1 (7 versions) | 3.13.14-1 | — |
| python3.14 | 3.14.0-1 ... 3.14.3-3 (17 versions) | 3.14.3-4 | — |
Debian:12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| python3.11 | 3.11.2-6 ... 3.11.2-6+deb12u7 (8 versions) | 3.11.2-6+deb12u8 | — |
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| python3.13 | 3.13.5-2 | 3.13.5-2+deb13u1 | — |
Weakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(1)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 7× in last 7d / 94× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 274 total refreshes for this CVE.
- 2026-09-04 13:59 UTCEPSS rescore
- 2026-09-04 05:05 UTCEPSS rescore
- 2026-09-02 19:40 UTCOSV refresh
- 2026-09-01 13:52 UTCEPSS rescore
- 2026-09-01 04:38 UTCEPSS rescore
- 2026-08-30 19:16 UTCEPSS rescore
- 2026-08-30 01:21 UTCEPSS rescore
- 2026-08-28 21:40 UTCEPSS rescore
- 2026-08-27 14:24 UTCEPSS rescore
- 2026-08-26 14:45 UTCEPSS rescore
- 2026-08-25 13:47 UTCEPSS rescore
- 2026-08-24 14:15 UTCEPSS rescore
- 2026-08-23 00:18 UTCEPSS rescore
- 2026-08-21 23:48 UTCEPSS rescore
- 2026-08-20 22:54 UTCEPSS rescore
- 2026-08-19 17:02 UTCEPSS rescore
- 2026-08-18 13:47 UTCEPSS rescore
- 2026-08-17 13:46 UTCEPSS rescore
- 2026-08-16 14:55 UTCEPSS rescore
- 2026-08-16 11:43 UTCEG score recompute
- 2026-08-16 11:43 UTCVendor advisory
- 2026-08-16 11:43 UTCGHSA enrichment
- 2026-08-16 02:13 UTCEPSS rescore
- 2026-08-16 02:13 UTCEPSS rescore
- 2026-08-15 01:29 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-08-14 23:59 UTCVendor advisory
- 2026-08-14 23:59 UTCGHSA enrichment
- 2026-08-14 20:05 UTCVendor advisory
- 2026-08-14 20:05 UTCGHSA enrichment
- 2026-08-14 15:32 UTCVendor advisory
- 2026-08-14 15:32 UTCGHSA enrichment
- 2026-08-14 11:37 UTCVendor advisory
- 2026-08-14 11:37 UTCGHSA enrichment
- 2026-08-14 07:43 UTCEG score recompute
- 2026-08-14 07:43 UTCVendor advisory
- 2026-08-14 07:43 UTCGHSA enrichment
- 2026-08-13 21:59 UTCEPSS rescore
- 2026-08-13 01:23 UTCVendor advisory
- 2026-08-13 01:23 UTCGHSA enrichment
- 2026-08-13 00:41 UTCVendor advisory
- 2026-08-13 00:41 UTCGHSA enrichment
- 2026-08-12 22:47 UTCEG score recompute
- 2026-08-12 22:47 UTCVendor advisory
- 2026-08-12 22:47 UTCGHSA enrichment
- 2026-08-12 13:49 UTCEPSS rescore
- 2026-08-12 01:37 UTCVendor advisory
- 2026-08-12 01:37 UTCGHSA enrichment
- 2026-08-11 21:43 UTCEG score recompute
- 2026-08-11 21:43 UTCVendor advisory
- 2026-08-11 21:43 UTCGHSA enrichment
- 2026-08-11 13:41 UTCEPSS rescore
- 2026-08-11 08:45 UTCVendor advisory
- 2026-08-11 08:45 UTCGHSA enrichment
- 2026-08-11 04:51 UTCEG score recompute
- 2026-08-11 04:51 UTCVendor advisory
- 2026-08-11 04:51 UTCGHSA enrichment
- 2026-08-10 23:59 UTCEPSS rescore
- 2026-08-10 13:06 UTCVendor advisory
- 2026-08-10 13:06 UTCGHSA enrichment
- 2026-08-10 09:12 UTCVendor advisory
- 2026-08-10 09:12 UTCGHSA enrichment
- 2026-08-10 05:19 UTCVendor advisory
- 2026-08-10 05:19 UTCGHSA enrichment
- 2026-08-10 01:11 UTCVendor advisory
- 2026-08-10 01:11 UTCGHSA enrichment
- 2026-08-09 21:15 UTCVendor advisory
- 2026-08-09 21:15 UTCGHSA enrichment
- 2026-08-09 17:21 UTCEG score recompute
- 2026-08-09 17:21 UTCVendor advisory
- 2026-08-09 17:21 UTCGHSA enrichment
- 2026-08-09 13:45 UTCEPSS rescore
- 2026-08-09 13:27 UTCVendor advisory
- 2026-08-09 13:27 UTCGHSA enrichment
- 2026-08-09 07:24 UTCEG score recompute
- 2026-08-09 07:24 UTCVendor advisory
- 2026-08-09 07:24 UTCGHSA enrichment
- 2026-08-08 09:43 UTCVendor advisory
- 2026-08-08 09:43 UTCGHSA enrichment
- 2026-08-08 05:49 UTCVendor advisory
- 2026-08-08 05:49 UTCGHSA enrichment
- 2026-08-08 01:55 UTCVendor advisory
- 2026-08-08 01:55 UTCGHSA enrichment
- 2026-08-07 21:59 UTCVendor advisory
- 2026-08-07 21:59 UTCGHSA enrichment
- 2026-08-07 18:05 UTCEG score recompute
- 2026-08-07 18:05 UTCVendor advisory
- 2026-08-07 18:05 UTCGHSA enrichment
- 2026-08-07 16:26 UTCEPSS rescore
- 2026-08-06 19:49 UTCEG score recompute
- 2026-08-06 19:49 UTCVendor advisory
- 2026-08-06 19:49 UTCGHSA enrichment
- 2026-08-06 13:45 UTCEPSS rescore
- 2026-08-06 10:30 UTCVendor advisory
- 2026-08-06 10:30 UTCGHSA enrichment
- 2026-08-06 05:50 UTCVendor advisory
- 2026-08-06 05:50 UTCGHSA enrichment
- 2026-08-06 01:56 UTCEG score recompute
- 2026-08-06 01:56 UTCVendor advisory
- 2026-08-06 01:56 UTCGHSA enrichment
- 2026-08-05 19:16 UTCEPSS rescore
Related CVEs(same vendor + same CWE)
Same vendor
10 shownredhat
- CVE-2001-0825EG 10.0HIGH
- CVE-2001-0554EG 10.0EPSS p98HIGH
- CVE-2001-0414EG 10.0EPSS p100HIGH
- CVE-2001-0191EG 10.0EPSS p92HIGH
- CVE-2001-0301EG 10.0EPSS p91HIGH
- CVE-2001-0197EG 10.0EPSS p96HIGH
- CVE-2001-0233EG 10.0EPSS p96HIGH
- CVE-2001-0010EG 10.0EPSS p98HIGH
- CVE-2001-0011EG 10.0EPSS p94HIGH
- CVE-2001-0013EG 10.0EPSS p96HIGH
Same CWE
10 shownCWE-20
- CVE-2004-1019EG 10.0EPSS p94HIGH
- CVE-2004-0840EG 10.0EPSS p98HIGH
- CVE-2003-1425EG 10.0EPSS p96HIGH
- CVE-2003-1487EG 10.0EPSS p94HIGH
- CVE-2002-1874EG 10.0HIGH
- CVE-2002-2236EG 10.0EPSS p91HIGH
- CVE-2002-2365EG 10.0HIGH
- CVE-2002-1358EG 10.0EPSS p93HIGH
- CVE-2002-1359EG 10.0EPSS p100HIGH
- CVE-2002-1360EG 10.0EPSS p93HIGH
Frequently asked(5)
What is CVE-2025-13462?
When was CVE-2025-13462 disclosed?
Is CVE-2025-13462 actively exploited?
What is the CVSS score of CVE-2025-13462?
How do I remediate CVE-2025-13462?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-13462
Is Your Infrastructure Affected by CVE-2025-13462?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.