{"api_version":"1","generated_at":"2026-08-04T08:02:38+00:00","cve":"CVE-2025-8194","urls":{"html":"https://cve.report/CVE-2025-8194","api":"https://cve.report/api/cve/CVE-2025-8194.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-8194","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-8194"},"summary":{"title":"Tarfile infinite loop during parsing with negative member offset","description":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","state":"PUBLISHED","assigner":"PSF","published_at":"2025-07-28 19:15:43","updated_at":"2026-07-31 14:16:45"},"problem_types":["CWE-835","CWE-835 CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')"],"metrics":[{"version":"3.1","source":"cna@python.org","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/python/cpython/pull/137027","name":"https://github.com/python/cpython/pull/137027","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","name":"https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2025/07/28/1","name":"http://www.openwall.com/lists/oss-security/2025/07/28/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2025/07/28/2","name":"http://www.openwall.com/lists/oss-security/2025/07/28/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","name":"https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","name":"https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","name":"https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","name":"https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","name":"https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/issues/130577","name":"https://github.com/python/cpython/issues/130577","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","name":"https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","name":"https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","name":"https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","refsource":"cna@python.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-8194","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8194","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Python Software Foundation","product":"CPython","version":"affected 3.9.24 python","platforms":[]},{"source":"CNA","vendor":"Python Software Foundation","product":"CPython","version":"affected 3.10.0 3.10.19 python","platforms":[]},{"source":"CNA","vendor":"Python Software Foundation","product":"CPython","version":"affected 3.11.0 3.11.14 python","platforms":[]},{"source":"CNA","vendor":"Python Software Foundation","product":"CPython","version":"affected 3.12.0 3.12.12 python","platforms":[]},{"source":"CNA","vendor":"Python Software Foundation","product":"CPython","version":"affected 3.13.0 3.13.6 python","platforms":[]},{"source":"CNA","vendor":"Python Software Foundation","product":"CPython","version":"affected 3.14.0a1 3.14.0rc2 python","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Alexander Urieles","lang":"en"},{"source":"CNA","value":"Seth Larson","lang":"en"},{"source":"CNA","value":"Ethan Furman","lang":"en"},{"source":"CNA","value":"Steve Dower","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"8194","cve":"CVE-2025-8194","epss":"0.006110000","percentile":"0.458730000","score_date":"2026-08-03","updated_at":"2026-08-04 00:07:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-8194","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-07-28T18:57:54.114655Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-07-28T18:57:59.093Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2025-11-04T22:06:48.390Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2025/07/28/1"},{"url":"http://www.openwall.com/lists/oss-security/2025/07/28/2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"CPython","repo":"https://github.com/python/cpython","vendor":"Python Software Foundation","versions":[{"lessThan":"3.9.24","status":"affected","version":"0","versionType":"python"},{"lessThan":"3.10.19","status":"affected","version":"3.10.0","versionType":"python"},{"lessThan":"3.11.14","status":"affected","version":"3.11.0","versionType":"python"},{"lessThan":"3.12.12","status":"affected","version":"3.12.0","versionType":"python"},{"lessThan":"3.13.6","status":"affected","version":"3.13.0","versionType":"python"},{"lessThan":"3.14.0rc2","status":"affected","version":"3.14.0a1","versionType":"python"}]}],"credits":[{"lang":"en","type":"reporter","value":"Alexander Urieles"},{"lang":"en","type":"coordinator","value":"Seth Larson"},{"lang":"en","type":"remediation reviewer","value":"Ethan Furman"},{"lang":"en","type":"remediation reviewer","value":"Steve Dower"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. <br><br>This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1\">https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1</a><div><br></div><br>"}],"value":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-835","description":"CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-31T14:01:18.178Z","orgId":"28c92f92-d60d-412d-b760-e73465c3df22","shortName":"PSF"},"references":[{"tags":["issue-tracking"],"url":"https://github.com/python/cpython/issues/130577"},{"tags":["patch"],"url":"https://github.com/python/cpython/pull/137027"},{"tags":["vendor-advisory"],"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe"},{"tags":["mitigation"],"url":"https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19"},{"tags":["patch"],"url":"https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb"}],"source":{"discovery":"UNKNOWN"},"title":"Tarfile infinite loop during parsing with negative member offset","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"28c92f92-d60d-412d-b760-e73465c3df22","assignerShortName":"PSF","cveId":"CVE-2025-8194","datePublished":"2025-07-28T18:42:44.847Z","dateReserved":"2025-07-25T14:05:55.899Z","dateUpdated":"2026-07-31T14:01:18.178Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-07-28 19:15:43","lastModifiedDate":"2026-07-31 14:16:45","problem_types":["CWE-835","CWE-835 CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')"],"metrics":{"cvssMetricV31":[{"source":"cna@python.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-28T18:57:54.114655Z","id":"CVE-2025-8194","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"8194","Ordinal":"1","Title":"Tarfile infinite loop during parsing with negative member offset","CVE":"CVE-2025-8194","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"8194","Ordinal":"1","NoteData":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","Type":"Description","Title":"Tarfile infinite loop during parsing with negative member offset"}]}}}