If the value passed to os.path.expandvars() is user-controlled a
performance degradation is possible when expanding environment
variables.

Subscriptions

Vendors Products
Python Software Foundation Subscribe
Cpython Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4445-1 python3.9 security update
Ubuntu USN Ubuntu USN USN-7886-1 Python vulnerabilities
Ubuntu USN Ubuntu USN USN-7886-2 Python vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Feb 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Python python
CPEs cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
Vendors & Products Python python
Metrics cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Mon, 01 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Python Software Foundation
Python Software Foundation cpython
CPEs cpe:2.3:a:python_software_foundation:cpython:*:*:*:*:*:*:*:*
Vendors & Products Python Software Foundation
Python Software Foundation cpython
References

Fri, 07 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Python
Python cpython
Vendors & Products Python
Python cpython

Fri, 31 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 17:30:00 +0000


Fri, 31 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
Description If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
Title Quadratic complexity in os.path.expandvars() with user-controlled template
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2026-03-03T14:43:01.737Z

Reserved: 2025-06-13T15:05:20.139Z

Link: CVE-2025-6075

cve-icon Vulnrichment

Updated: 2025-10-31T17:55:10.898Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-31T17:15:48.693

Modified: 2026-02-04T19:05:15.007

Link: CVE-2025-6075

cve-icon Redhat

Severity : Low

Publid Date: 2025-10-31T16:41:34Z

Links: CVE-2025-6075 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-11-03T10:43:59Z

Weaknesses