CVE-2025-4435

EUVD-2025-16725
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
PSFCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pythoncpython
𝑥
< 3.9.23
CNA
pythoncpython
3.10.0 ≤
𝑥
< 3.10.18
CNA
pythoncpython
3.11.0 ≤
𝑥
< 3.11.13
CNA
pythoncpython
3.12.0 ≤
𝑥
< 3.12.11
CNA
pythoncpython
3.13.0 ≤
𝑥
< 3.13.4
CNA
Debian logo
Debian Releases
Debian Product
Codename
jython
bookworm
2.7.3+repack1-1
fixed
bullseye
2.7.2+repack1-3
fixed
forky
2.7.3+repack1-1
fixed
sid
2.7.3+repack1-1
fixed
trixie
2.7.3+repack1-1
fixed
pypy3
bookworm
no-dsa
bullseye
7.3.5+dfsg-2+deb11u2
fixed
bullseye (security)
7.3.5+dfsg-2+deb11u5
fixed
forky
7.3.21+dfsg-4
fixed
sid
7.3.21+dfsg-4
fixed
trixie
no-dsa
python2.7
bullseye
2.7.18-8+deb11u1
fixed
python3.11
bookworm
3.11.2-6+deb12u6
fixed
bookworm (security)
3.11.2-6+deb12u3
fixed
python3.13
forky
3.13.12-1
fixed
sid
3.13.12-1
fixed
trixie
3.13.5-2
fixed
python3.9
bullseye
3.9.2-1
fixed
bullseye (security)
3.9.2-1+deb11u6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
xenial
not-affected
python3.4
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
python3.5
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
not-affected
xenial
not-affected
python3.6
bionic
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.7
bionic
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.8
bionic
not-affected
focal
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.9
focal
not-affected
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.10
jammy
not-affected
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.11
jammy
not-affected
noble
dne
oracular
dne
plucky
dne
questing
dne
python3.12
jammy
dne
noble
Fixed 3.12.3-1ubuntu0.7
released
oracular
Fixed 3.12.7-1ubuntu2.2
released
plucky
dne
questing
dne
python3.13
jammy
dne
noble
dne
oracular
Fixed 3.13.0-1ubuntu0.3
released
plucky
Fixed 3.13.3-1ubuntu0.2
released
questing
not-affected
python3.14
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
Fixed 3.14.0-1
released