CVE-2025-6075
MediumAdvisory
Published 31 Oct 2025In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 479
- of 17,787 indexed, latest versions
- Container images
- 457
- deployed by those charts
- Fix available
- 12 of 12
- affected packages
Quadratic complexity in os.path.expandvars() with user-controlled template
Carried by container images the latest versions of 479 of 17,787 indexed charts deploy, on 457 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.2-6, 3.11.2-6+deb12u2, 3.11.2-6+deb12u3+3 more | 3.11.0~rc1-1~22.04.1~esm6, 3.11.2-6+deb12u7 | 144 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | 3.8.10-0ubuntu1~20.04.18+esm3 | 100 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+13 more | 3.10.12-1~22.04.12 | 63 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+12 more | 2.7.12-1ubuntu0~16.04.18+esm21 | 54 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | 3.6.9-1~18.04ubuntu1.13+esm7 | 44 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+3 more | 3.12.3-1ubuntu0.9 | 27 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | 3.5.2-2ubuntu0~16.04.13+esm20 | 25 |
| python3.13deb | 3.13.5-2, 3.13.5-2+e30 | 3.13.5-2+deb13u1, 3.13.5-2+e36 | 22 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | 3.4.3-1ubuntu1~14.04.7+esm17 | 7 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.9.25 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.12-r2 | 2 |
| python-3.13apk | 3.13.7-r0 | 3.13.9-r2 | 1 |
- OSV records
- BIT-python-2025-6075DEBIAN-CVE-2025-6075UBUNTU-CVE-2025-6075CGA-2wvx-2w83-vmwcCGA-cf2q-rh6v-4j4qECHO-a643-f216-2dc6
- Also known as
- BIT-libpython-2025-6075, BIT-python-min-2025-6075, CGA-7xhq-pvfp-j428, CGA-vf4f-pq29-9jqf, PSF-2025-13, USN-7886-1, USN-8614-1
Charts affected
479 by stars
Container images carrying it
457 by charts deploying them
A fixed version is listed for 12 of the 12 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| public.ecr.aws/ | 046ef5c9ed50 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| public.ecr.aws/ | 573779e57fae | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm3 | 1 |
| public.ecr.aws/ | f74851ce31f5 | python3.11 | 3.11.2-6+deb12u7 | 1 |
| quay.io/ | a2d3a4c67b0f | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm7 | 1 |
| quay.io/ | e0d9b93dbf2b | python3.11 | 3.11.2-6+deb12u7 | 1 |
| registry.gitlab.com/ | f6385712935f | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm3 | 1 |
| registry.k8s.io/ | ce5b5ccd5eb0 | python3.11 | 3.11.2-6+deb12u7 | 1 |