/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vr9h-w849-v74m

Published

Last updated

https://images.chainguard.dev/security/CGA-vr9h-w849-v74m
Package

python-3.13

RepositoryWolfi
Latest Update
Fixed
Fixed Version

3.13.6-r0

Aliases
  • CVE-2025-8194
  • GHSA-v594-44hm-2j7p

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-8194

Updates

Status

Fixed

Fixed version

3.13.6-r0

Status

Pending upstream fix

Impact

The tarfile validation fix from gh-130577 has been cherry-picked from Python 3.13 main branch to our python-3.13 package. However, this remains a pending-upstream-fix until an official Python 3.13.6+ release includes this security fix. The cherry-pick provides immediate protection while waiting for the upstream release.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing