CVE-2025-4516

Updated: 2026-01-10 02:42:14.150201

Description:

There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 5.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 8.4 ELS python3 3.6.8 5.1 MEDIUM Released CLSA-2026:1767700458 2026-01-06 16:03:26
CentOS 8.4 ELS python2 2.7.18 5.1 MEDIUM In Testing 2025-12-30 11:31:49
CentOS 8.5 ELS python2 2.7.18 5.1 MEDIUM In Testing 2025-12-30 11:31:48
CentOS 8.5 ELS python3 3.6.8 5.1 MEDIUM Released CLSA-2026:1767700070 2026-01-06 16:03:27
CentOS Stream 8 ELS python2 2.7.18 5.1 MEDIUM In Testing 2025-12-30 11:31:49
Ubuntu 18.04 ELS python3.6 3.6.9-1 5.1 MEDIUM Released CLSA-2025:1753209049 2025-07-23 02:13:34