Back

MEDIUM

Use-after-free in "unicode_escape" decoder with error handler

Published May 15, 2025

Description

There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PSF
Published May 15, 2025
Updated Jul 31, 2026
Reserved May 9, 2025
CISA Vulnrichment
Updated May 15, 2025
NVD
Status Deferred
Modified Jul 31, 2026
Red Hat
Severity Moderate
Public date May 15, 2025