Skip to main content
EPSS 0.6%top 51%

CVE-2025-8194: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Python Software Foundation CPython

0
High
VulnerabilityCVE-2025-8194cvecve-2025-8194cwe-835
Published: 07/28/2025 (07/28/2025, 18:42:44 UTC)
Source: CVE Database V5
Vendor/Project: Python Software Foundation
Product: CPython

Description

CVE-2025-8194 is a high severity vulnerability in the Python Software Foundation's CPython implementation affecting the tarfile module. The flaw causes the TarFile extraction and entry enumeration APIs to enter an infinite loop when processing tar archives with negative offsets. This results in deadlock during parsing of maliciously crafted tar files. The vulnerability affects specific CPython versions including 3.10.0 through 3.14.0a1. No official patch is listed, but a mitigation patch is available as a third-party workaround.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

GitHub Actionsmore threats →ai
python/cpython
pkg:github/python/cpython
Affected versions
=3.10.0=3.11.0=3.12.0=3.13.0=3.14.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 15:00:26 UTC

Technical Analysis

The vulnerability in CPython's tarfile module arises from improper handling of tar archives containing negative offsets. The TarFile extraction and entry enumeration APIs do not error on these negative offsets, causing an infinite loop and deadlock during parsing. This defect is classified under CWE-835 (Loop with Unreachable Exit Condition). The affected versions explicitly include CPython 3.10.0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, and 3.14.0a1. The CVSS v3.1 score is 7.5, indicating high severity with network attack vector, low attack complexity, no privileges or user interaction required, and impact limited to availability (denial of service). No official vendor patch is referenced, but a mitigation patch is available via a third-party gist.

Potential Impact

Successful exploitation causes an infinite loop and deadlock in the tarfile module during parsing of malicious tar archives. This results in denial of service by making the process hang indefinitely. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.

Mitigation Recommendations

No official patch from the Python Software Foundation is currently referenced. A third-party mitigation patch is available and can be applied after importing the tarfile module as a temporary fix. Users should monitor the official Python advisories for an official fix. Until then, applying the provided patch mitigates the infinite loop condition.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
PSF
Date Reserved
2025-07-25T14:05:55.899Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6887c950ad5a09ad00867b28

Added to database: 07/28/2025, 19:02:40 UTC

Last enriched: 08/07/2026, 15:00:26 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 256

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses