CVE Explorer
CVE-2025-8291
The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Loc
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"CPython","repo":"https://github.com/python/cpython","vendor":"Python Software Foundation","versions":[{"lessThan":"3.9.24","status":"affected","version":"0","versionType":"python"},{"lessThan":"3.10.19","status":"affected","version":"3.10.0","versionType":"python"},{"lessThan":"3.11.14","status":"affected","version":"3.11.0","versionType":"python"},{"lessThan":"3.12.12","status":"affected","version":"3.12.0","versionType":"python"},{"lessThan":"3.13.10","status":"affected","version":"3.13.0","versionType":"python"},{"lessThan":"3.14.1","status":"affecte…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1285","description":"CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
12 source assertions{"tags":["technical-description","exploit"],"url":"https://github.com/google/security-research/security/advisories/GHSA-hhv7-p4pg-wm6p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/adp/0/references/1
{"tags":["vendor-advisory"],"url":"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2025-12.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/adp/0/references/0
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/162997bb70e067668c039700141770687bc8f267"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/3
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/1d29afb0d6218aa8fb5e1e4a6133a4778d89bb46"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/5
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/333d4a6f4967d3ace91492a39ededbcf3faa76a6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/4
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/76437ac248ad8ca44e9bf697b02b1e2241df2196"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/6
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/8392b2f0d35678407d9ce7d95655a5b77de161b4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/7
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/bca11ae7d575d87ed93f5dd6a313be6246e3e388"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/8
{"tags":["patch"],"url":"https://github.com/python/cpython/commit/d11e69d6203080e3ec450446bfed0516727b85c3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/9
{"tags":["issue-tracking"],"url":"https://github.com/python/cpython/issues/139700"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/2
{"tags":["patch"],"url":"https://github.com/python/cpython/pull/139702"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/QECOPWMTH4VPPJAXAH2BGTA4XADOP62G/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:684ca4322b72177a4fe99cfa89b33a9e8a703c14a2c98315f67d0b0b46c7c0a4 · sha256:d47cfb461ac35d54… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.