CVE detail
CVE-2025-13462 — CVE-2025-13462
Published 2026-03-12 · Modified 2026-08-13 · Vendor python · Product python · Source nvd
LOW
severity
CVSS-derived band
0.0016
EPSS probability
exploitation probability, 30d
6.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References