Rapid7

vulnerability

Ubuntu: (Multiple Advisories) (CVE-2025-6075): Python vulnerabilities

Severity
5
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:C)
Published
Oct 31, 2025
Added
Nov 25, 2025
Modified
Apr 16, 2026

Description

If the value passed to os.path.expandvars() is user-controlled a
performance degradation is possible when expanding environment
variables.

Solutions

ubuntu-pro-upgrade-idle-python3-11ubuntu-pro-upgrade-libpython3-4ubuntu-pro-upgrade-libpython3-5ubuntu-pro-upgrade-libpython3-6ubuntu-pro-upgrade-libpython3-7ubuntu-pro-upgrade-libpython3-8ubuntu-pro-upgrade-libpython3-9ubuntu-pro-upgrade-python3-11ubuntu-pro-upgrade-python3-4ubuntu-pro-upgrade-python3-5ubuntu-pro-upgrade-python3-6ubuntu-pro-upgrade-python3-7ubuntu-pro-upgrade-python3-8ubuntu-pro-upgrade-python3-9ubuntu-upgrade-libpython3-10ubuntu-upgrade-libpython3-12t64ubuntu-upgrade-libpython3-13ubuntu-upgrade-python3-10ubuntu-upgrade-python3-12ubuntu-upgrade-python3-13

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.