CVE-2025-8194: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Python Software Foundation CPython
CVE-2025-8194 is a high severity vulnerability in the Python Software Foundation's CPython implementation affecting the tarfile module. The flaw causes the TarFile extraction and entry enumeration APIs to enter an infinite loop when processing tar archives with negative offsets. This results in deadlock during parsing of maliciously crafted tar files. The vulnerability affects specific CPython versions including 3.10.0 through 3.14.0a1. No official patch is listed, but a mitigation patch is available as a third-party workaround.
AI Analysis
Technical Summary
The vulnerability in CPython's tarfile module arises from improper handling of tar archives containing negative offsets. The TarFile extraction and entry enumeration APIs do not error on these negative offsets, causing an infinite loop and deadlock during parsing. This defect is classified under CWE-835 (Loop with Unreachable Exit Condition). The affected versions explicitly include CPython 3.10.0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, and 3.14.0a1. The CVSS v3.1 score is 7.5, indicating high severity with network attack vector, low attack complexity, no privileges or user interaction required, and impact limited to availability (denial of service). No official vendor patch is referenced, but a mitigation patch is available via a third-party gist.
Potential Impact
Successful exploitation causes an infinite loop and deadlock in the tarfile module during parsing of malicious tar archives. This results in denial of service by making the process hang indefinitely. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.
Mitigation Recommendations
No official patch from the Python Software Foundation is currently referenced. A third-party mitigation patch is available and can be applied after importing the tarfile module as a temporary fix. Users should monitor the official Python advisories for an official fix. Until then, applying the provided patch mitigates the infinite loop condition.
CVE-2025-8194: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Python Software Foundation CPython
Description
CVE-2025-8194 is a high severity vulnerability in the Python Software Foundation's CPython implementation affecting the tarfile module. The flaw causes the TarFile extraction and entry enumeration APIs to enter an infinite loop when processing tar archives with negative offsets. This results in deadlock during parsing of maliciously crafted tar files. The vulnerability affects specific CPython versions including 3.10.0 through 3.14.0a1. No official patch is listed, but a mitigation patch is available as a third-party workaround.
CVSS v3.1
Score 7.5high
Affected software
pkg:github/python/cpythonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in CPython's tarfile module arises from improper handling of tar archives containing negative offsets. The TarFile extraction and entry enumeration APIs do not error on these negative offsets, causing an infinite loop and deadlock during parsing. This defect is classified under CWE-835 (Loop with Unreachable Exit Condition). The affected versions explicitly include CPython 3.10.0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, and 3.14.0a1. The CVSS v3.1 score is 7.5, indicating high severity with network attack vector, low attack complexity, no privileges or user interaction required, and impact limited to availability (denial of service). No official vendor patch is referenced, but a mitigation patch is available via a third-party gist.
Potential Impact
Successful exploitation causes an infinite loop and deadlock in the tarfile module during parsing of malicious tar archives. This results in denial of service by making the process hang indefinitely. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.
Mitigation Recommendations
No official patch from the Python Software Foundation is currently referenced. A third-party mitigation patch is available and can be applied after importing the tarfile module as a temporary fix. Users should monitor the official Python advisories for an official fix. Until then, applying the provided patch mitigates the infinite loop condition.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- PSF
- Date Reserved
- 2025-07-25T14:05:55.899Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6887c950ad5a09ad00867b28
Added to database: 07/28/2025, 19:02:40 UTC
Last enriched: 08/07/2026, 15:00:26 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 256
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.