python-3.9
Chainguard
7.5
CVSS V3
Status
Impact
Upstream maintainers must release the backport PR for Python 3.9. The tarfile validation fix from gh-130577 is ready for 3.9 via PR #137177 but not yet merged and released. CVE-2025-8194 is fixed in Python 3.13.5+ but requires backporting to 3.9 branch. Reference: https://github.com/python/cpython/pull/137177
Status