nhairs / nhairs/python-json-logger
CVE-2025-27607/GHSA-wmxh-pxcx-9w24 is likely causing more panic than necessary
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 270
- Forks
- 21
- PR merge metrics
- No merged PRs in 30d
Description
Hello @nhairs!
The recently published advisory CVE-2025-27607 details a name resurrection attack that is no longer possible (as the name has been reserved by PyPI admins) and was never exploited. This doesn't line up with the CVE severity score of 8.8 which is now causing likely some panic for users who think certain versions of this library are actively exploitable.
I suggest the following:
- Update the advisory to a CVSS score of 0.0 (this is valid for "informational" advisories)
- Update the advisory with a note that this is no longer exploitable and no action is required at this time, even for users using "affected" versions named in the advisory.
Happy to answer questions!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the CVE-2025-27607/GHSA-wmxh-pxcx-9w24 advisory and the concerns recorded in this issue. Done means the advisory has a CVSS score of 0.0 and clearly states that the name is reserved, exploitation is no longer possible, and affected users need take no action.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 40/100