Back to Database
Status published
Low
CVE-2025-6075
Quadratic complexity in os.path.expandvars() with user-controlled template
Vulnerability Description
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6075
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/python/cpython/issues/136065
- https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/
- https://github.com/python/cpython/commit/2e6150adccaaf5bd95d4c19dfd04a36e0b325d8c
- https://github.com/python/cpython/commit/631ba3407e3348ccd56ce5160c4fb2c5dc5f4d84
- https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca
- https://github.com/python/cpython/commit/9ab89c026aa9611c4b0b67c288b8303a480fe742
- https://github.com/python/cpython/commit/c8a5f3435c342964e0a432cc9fb448b7dbecd1ba
- https://github.com/python/cpython/commit/f029e8db626ddc6e3a3beea4eff511a71aaceb5c
- https://github.com/python/cpython/commit/5dceb93486176e6b4a6d9754491005113eb23427
More from Python Software Foundation
View All →CVE-2025-8291
ZIP64 End of Central Directory (EOCD) Locator record offset not checked
Medium
4.3
CVE-2025-8194
Tarfile infinite loop during parsing with negative member offset
High
7.5
CVE-2025-6069
HTMLParser quadratic complexity when processing malformed inputs
Medium
4.3
CVE-2025-4517
Arbitrary writes via tarfile realpath overflow
Critical
9.4
CVE-2025-4516
Use-after-free in "unicode_escape" decoder with error handler
Medium
5.9
Affected Vendor
Python Software Foundation
View all reports →Affected Software
CPython
Vulnerable Versions:
0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, 3.15.0a1
Timeline
Official Publish:
October 31st, 2025
Last Modified:
March 3rd, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.