CVE-2025-13462Disclosure(python / python)

MEDIUMCVSS 3.3 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch python python systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-74CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • python

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • False Positive: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
python

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-04-15: 1Mentions · 2026-06-10: 1Active Exploitation · 2026-03-13: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-15: 1Technical Details · 2026-06-10: 103-1203-1304-1506-10
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
False Positive
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-131
Active Exploitation1
2026-04-151
Disclosure1
2026-06-101
False Positive1
Full discourse4 posts
  • JFrog Security@JFrogSecurity
    False Positive

    ⚠️ Overhyped vulnerability of the week: CVE severity inflation strikes with CVE-2025-13462. The issue is a TAR parser discrepancy in Python's `tarfile` module, where a specially crafted archive may be interpreted differently than other TAR implementations. While NVD scored this CVE as Critical (CVSS 9.8), the publicly disclosed impact includes: ❌ No RCE ❌ No arbitrary file write ❌ No "guaranteed" impact of any kind Furthermore, the CVE received a LOW severity rating in Python's original advisory. The only realistic security impact is in systems that mix using Python's TAR parser with other TAR parsers, and make security decisions based on this parsing. This may lead to a validation vs. execution mismatch. We believe that the advisory's low-severity rating is much more fitting in this case.

    Post summary

    The tweet argues that CVE‑2025‑13462 is a TAR parser discrepancy with no real impact such as RCE or file write, and that its critical CVSS score is inflated; it presents the issue as a debunked, low‑risk vulnerability.

    1402351.8K
    5.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-13462 impacts python in 6 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/475 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A newly identified high‑severity CVE (CVE‑2025‑13462) affecting Python in six AWS Lambda base images is disclosed with issue links, but no PoC, exploit, patch, or active exploitation details are provided.

    00000223
    34 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎙️ RadioCSIRT Ep.596 – Édition du vendredi 13 mars 2026 Cinq sujets. Un fil rouge : des Zero-Day activement exploités, des données sensibles exposées et le renforcement des capacités CSIRT en Afrique. 🔴 CISA KEV : trois nouvelles entrées en exploitation active. CVE-2026-3909 (Google Skia – Out-of-Bounds Write), CVE-2026-3910 (Google Chromium V8 – implémentation incorrecte), CVE-2025-68613 (n8n – exécution de code via ressources dynamiques). 🔴 Google Chrome : patch hors cycle en urgence. Deux Zero-Day corrigés, exploitables à distance via simple visite d'une page malveillante. Versions protégées : 146.0.7680.75/76 sur Windows et macOS, 146.0.7680.75 sur Linux. 🔴 CERT-FR : trois avis publiés ce vendredi. CERTFR-2026-AVI-0294 – CVE-2026-26133, atteinte à la confidentialité dans Microsoft Office sur Android, iOS et macOS. CERTFR-2026-AVI-0285 – CVE-2025-13462, vulnérabilité dans CPython, nature non précisée. CERTFR-2026-AVI-0289 – multiples failles dans le noyau Linux d'Ubuntu 22.04 LTS et 24.04 LTS, quatre CVE référencées. 🔴 Quittr : misconfiguration Firebase expose pendant plusieurs mois les données sensibles de plus de 600 000 utilisateurs d'une application de lutte contre la dépendance à la pornographie. Environ 100 000 profils de mineurs concernés. Alerte initiale ignorée depuis septembre 2025. 🔴 FIRST – African Regional Liaison : bilan deux ans. 1 210 professionnels soutenus, 50 initiatives, 33 pays, 70 CSIRTs engagés. Programme Train-the-Trainer actif dans sept pays africains. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-596-votre-actualite-cybersecurite-du-vendredi-13-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Chrome #ZeroDay #Skia #V8 #Chromium #Quittr #Firebase #DataLeak #DataBreach #MicrosoftOffice #Python #CPython #Ubuntu #Linux #CERTFR #FIRST #AfricaCyber #CSIRT #n8n #CVE #InfoSec #CERT #SOC #CISO #VOC #Patch

    Post summary

    Podcast covers three CISA KEV vulnerabilities actively exploited, recent out‑of‑cycle patches for Google Chrome, and data exposure incidents, emphasizing the urgency of patching.

    0000098
    412 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13462 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUT… https://www.cve.org/CVERecord?id=CVE-2025-13462

    Post summary

    The post presents a brief technical disclosure of CVE‑2025‑13462, detailing an issue in Python’s tarfile module’s normalization process, with no PoC, exploit, or patch mentioned.

    00000172
    56.7K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpython---
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--

Explore more