CVE-2025-6075

MEDIUM WAF: Medium
CVSS 5.5 Published: 2025-10-31
CWE-400

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
pythonpythonup to 3.9.0
pythonpython3.13.1 - 3.13.11
pythonpython3.14.0 - 3.14.1
pythonpython3.15.0

References

Back to CVE Database