CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-13462

lowcovered by 2 sourcesfirst seen 2026-07-06
It was discovered that Python incorrectly normalized paths in the tarfile module. An attacker could possibly use this issue to bypass path restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-13462) It was discovered that Python's HTMLParser incorrectly handled certain malformed HTML input. An attacker could possibly use this issue to cause Python to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534) It was discovered that Python's email module incorrectly quoted newlines in headers. An attacker could possibly use this issue to inject arbitrary email headers. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-1299) It was discovered that Python's http.client module did not properly sanitize carriage return and linefeed characters when handling HTTP CONNECT tunnel request headers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1502) It was discovered that Python's importlib module did not generate an audit event when loading legacy .pyc files. An attacker could possibly use this issue to bypass auditing mechanisms. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-2297) It was discovered that Python's unicodedata.normalize() function had incorrect algorithmic complexity. An attacker could possibly use this issue to cause Python to consume excessive resources, leading to a denial of service. (CVE-2026-3276) It was discovered that Python's http.cookies module incorrectly handled control characters in certain cookie operations. An attacker could possibly use this issue to inject arbitrary content. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644) It was discovered that the Python pyexpat module was vulnerable to unbounded recursion in the Expat XML parser. An attacker could possibly use this issue to cause Python to crash, resulting in a denial of serv

CSIRTS triage

What
A local attacker can exploit a vulnerability in CPython to manipulate files.
Who is affected
Local deployments of CPython are affected.
Urgency
Remediation is low urgency as the severity is low and exploitation is not reported.
Action
Monitor for updates from CPython.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-13462

Get an email if CVE-2025-13462 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2025-13462

CVE.org record

Embed the live status

CVE-2025-13462 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-13462 status](https://www.csirts.com/badge/CVE-2025-13462)](https://www.csirts.com/cve/CVE-2025-13462)