CVE-2025-12781
MediumAdvisory
Published 21 Jan 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 651
- of 17,787 indexed, latest versions
- Container images
- 645
- deployed by those charts
- Fix available
- 3 of 15
- affected packages
base64.b64decode() always accepts "+/" characters, despite setting altchars
Carried by container images the latest versions of 651 of 17,787 indexed charts deploy, on 645 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python-3.12apk | 3.12.0-r1, 3.12.9-r1, 3.12.14-r2, 3.12.14-r6 | no fix listed | 8 |
| python-3.14apk | 3.14.2-r2, 3.14.4-r2, 3.14.6-r0 | 3.14.6-r1 | 6 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.15.0 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.14-r0 | 3 |
| python-3.11apk | 3.11.16-r5 | no fix listed | 1 |
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | no fix listed | 180 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | no fix listed | 100 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+11 more | no fix listed | 87 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more | no fix listed | 80 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4, 3.13.7-1ubuntu0.1 | no fix listed | 74 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | no fix listed | 54 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | no fix listed | 44 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | no fix listed | 25 |
| python3.14deb | 3.14.4-1, 3.14.4-1ubuntu0.1, 3.14.4-1ubuntu0.2 | no fix listed | 9 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | no fix listed | 7 |
- OSV records
- BIT-python-2025-12781CGA-3mjq-5c23-prmpCGA-4mf7-96v4-52mjCGA-8w6w-j788-x97qCGA-p288-9mv5-m48fDEBIAN-CVE-2025-12781UBUNTU-CVE-2025-12781
- Also known as
- BIT-libpython-2025-12781, BIT-python-min-2025-12781, CGA-m2h9-8f76-h5pw, CGA-qm9w-v5cx-mm74, CGA-x4f5-663c-vj94, CGA-xp35-jg4m-v7xg, PSF-2026-7
Charts affected
651 by stars
Container images carrying it
645 by charts deploying them
A fixed version is listed for 3 of the 15 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| shaowenchen/ | 315444f703f4 | python3.10 | no fix listed | 1 |
| signalen/ | 760256000738 | python3.11 | no fix listed | 1 |
| sismics/ | f4b0ef019cf1 | python3.6 | no fix listed | 1 |
| sissbruecker/ | a222fb777e1f | python3.11 | no fix listed | 1 |
| snipe/ | 141ebf2386fe | python3.12 | no fix listed | 1 |
| snipe/ | 55fb7636a98c | python3.8 | no fix listed | 1 |
| socialmediamacroscope/ | 70fb11d4f531 | python3.8 | no fix listed | 1 |
| socialmediamacroscope/ | 19d3d26d53ee | python3.6 | no fix listed | 1 |
| socialmediamacroscope/ | 6418f9bdb4d2 | python3.11 | no fix listed | 1 |
| socialmediamacroscope/ | f508216be63c | python3.6 | no fix listed | 1 |
| socialmediamacroscope/ | b351c21422e6 | python3.11 | no fix listed | 1 |
| socialmediamacroscope/ | ca863306314b | python3.11 | no fix listed | 1 |
| socialmediamacroscope/ | fa490acac2f8 | python3.11 | no fix listed | 1 |
| someblackmagic/ | 6eca64b6b440 | python3.8 | no fix listed | 1 |
| sonroyaalmerol/ | 3f60f3abe990 | python3.13 | no fix listed | 1 |
| speckle/ | 2faf1508c1d3 | python3.11 | no fix listed | 1 |
| speckle/ | 3c8fbe855665 | python3.11 | no fix listed | 1 |
| speckle/ | 738c77eb6f97 | python3.11 | no fix listed | 1 |
| speckle/ | 81335b40696a | python3.11 | no fix listed | 1 |
| speckle/ | b696ac5022ab | python3.11 | no fix listed | 1 |
| speckle/ | cf72ad0f25fb | python3.11 | no fix listed | 1 |
| speckle/ | d6790a97ad47 | python3.11 | no fix listed | 1 |
| speckle/ | ff1641ac3f1b | python3.11 | no fix listed | 1 |
| sslhep/ | 1d12f943cec5 | python3.13 | no fix listed | 1 |
| sslhep/ | e7aff7f97b89 | python3.13 | no fix listed | 1 |
| sslhep/ | b01b8ee966ed | python3.13 | no fix listed | 1 |
| sslhep/ | 0e4175a4e1eb | python3.13 | no fix listed | 1 |
| sslhep/ | 671980005c57 | python3.13 | no fix listed | 1 |
| sslhep/ | 596db2abdd09 | python3.13 | no fix listed | 1 |
| sslhep/ | 54aaf1721d03 | python3.13 | no fix listed | 1 |
| sslhep/ | 2cb88ceab5bb | python3.13 | no fix listed | 1 |
| sslhep/ | c284442b44e3 | python3.13 | no fix listed | 1 |
| stackstorm/ | 88235ba70cad | python3.8 | no fix listed | 1 |
| stackstorm/ | 6f56d239d280 | python3.8 | no fix listed | 1 |
| stackstorm/ | 33ecfda16608 | python3.8 | no fix listed | 1 |
| stackstorm/ | 4e3f8c7ca52d | python3.8 | no fix listed | 1 |
| stackstorm/ | f190a6212195 | python3.8 | no fix listed | 1 |
| stackstorm/ | 259503496ff9 | python3.8 | no fix listed | 1 |
| stackstorm/ | b1de2055c362 | python3.8 | no fix listed | 1 |
| stackstorm/ | b1a338f64773 | python3.8 | no fix listed | 1 |
| stackstorm/ | 1c8904a3bf67 | python3.8 | no fix listed | 1 |
| stackstorm/ | 1bf35bfaf00c | python3.8 | no fix listed | 1 |
| stackstorm/ | 19fdfffdbba8 | python3.8 | no fix listed | 1 |
| stashapp/ | 24dbd7607174 | python3.8 | no fix listed | 1 |
| statcan/ | 3921305425b8 | python3.8 | no fix listed | 1 |
| streamnative/ | 11bceacec8fb | python3.8 | no fix listed | 1 |
| substratusai/ | 61695be635eb | python3.11 | no fix listed | 1 |
| supabase/ | aa1c92c0cf32 | python3.11 | no fix listed | 1 |
| supabase/ | d3aa0c86c7b3 | python3.13 | no fix listed | 1 |
| supabase/ | 26d8070c55e9 | python3.11 | no fix listed | 1 |