LiveActive security incident?Get immediate response
CVE Record

CVE-2025-8194: Tarfile infinite loop during parsing with negative member offset

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CPython’s tarfile module can become stuck indefinitely when parsing a malicious tar archive containing negative member offsets. Affected services may stop responding or exhaust worker capacity, causing denial of service. The supplied evidence does not indicate data theft, code execution, or data modification.

Executive priority

Prioritize internet-facing upload services and business-critical archive pipelines. Remediate promptly where untrusted tar files are processed because one malicious archive could stall workers and disrupt availability. Lower priority applies where tarfile is absent or all archive inputs are trusted and tightly controlled.

Technical view

TarFile extraction and entry-enumeration APIs accept negative member offsets without raising an error. Parsing can then enter an infinite loop and deadlock, producing an availability failure classified as CWE-835. Remote impact depends on an application accepting and processing attacker-controlled tar archives.

Likely exposure

Highest exposure exists in Python services, automation, upload handlers, and archive-processing pipelines that use tarfile with untrusted archives. The bundle lists CPython version starting points from 3.10.0 through 3.14.0a1, but does not clearly specify complete affected or fixed ranges.

Exploitation context

The CVSS 3.1 score is 7.5 with network reachability, low complexity, no privileges, and no user interaction. However, remote exploitation requires an exposed application path that parses attacker-supplied tar data. The bundle reports no KEV listing and provides no evidence of active exploitation.

Researcher notes

This is an availability-only parsing flaw based on the supplied CVSS vector and description; no confidentiality or integrity impact is established. Assess transitive tarfile use, worker concurrency, timeout behavior, and recovery controls. Exact affected and fixed release boundaries are insufficiently represented in the bundle and should be confirmed with vendor guidance.

Mitigation direction

  • Review the Python security announcement and determine the vendor-supported fixed release for each deployed branch.
  • Upgrade affected Python runtimes according to confirmed vendor guidance and distribution-specific advisories.
  • If immediate upgrades are impossible, evaluate the linked vendor-provided mitigation patch.
  • Restrict or suspend processing of untrusted tar archives until remediation is verified.
  • Apply resource limits and isolation around archive-processing workers to reduce denial-of-service impact.

Validation and detection

  • Inventory Python runtime versions and applications importing or indirectly using tarfile.
  • Trace whether external users, partners, or automated feeds can supply tar archives.
  • Confirm deployed code includes the upstream negative-offset validation or documented mitigation.
  • Use a controlled, non-production regression test to verify malformed archives terminate safely.
  • Monitor archive-processing workers for hangs, timeouts, queue growth, and abnormal resource consumption.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-835: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-8194 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
12Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6PSF

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2025-8194Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Python Software FoundationCPython0, 3.10.0, 3.11.0, 3.12.0, 3.13.0, 3.14.0a1unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-835 · source CWE mapping

Loop with Unreachable Exit Condition ('Infinite Loop')

Loop with Unreachable Exit Condition ('Infinite Loop') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.