aws / aws/aws-lambda-base-images
CVE-2025-13836 (CRITICAL) in python:3.14 image
Open
- Dominant language
- No language data
- Stars
- 777
- Forks
- 118
- PR merge metrics
- No merged PRs in 30d
Description
public.ecr.aws/lambda/python:3.14 is currently on 3.14.0 which has the following CVE against it: https://github.com/advisories/GHSA-399h-rrqc-rpgv
CVSS 3 has this as a CRITICAL (CVSS has it as MEDIUM) https://nvd.nist.gov/vuln/detail/CVE-2025-13836
Please update Python to 3.14.1 to mitigate this. Thanks!
Contributor guide
Assessment
This issue has not been assessed yet.