CVE 1.8 LOW

Quadratic complexity in os.path.expandvars() with user-controlled template_CVE-2025-6075

1.8 / 10
LOW
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

If the value passed to os.path.expandvars() is user-controlled a
performance degradation is possible when expanding environment
variables.

Basic Information

ID CVE-2025-6075
Source PSF
Published Oct 31, 2025 at 16:41
Modified Oct 31, 2025 at 17:55

Affected Product

Vendor Python Software Foundation
Product CPython
Affected Versions Python Software Foundation CPython 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.