nhairs / nhairs/python-json-logger

CVE-2025-27607/GHSA-wmxh-pxcx-9w24 is likely causing more panic than necessary

Open
#43 10 comments 4 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

waiting
Dominant language
Python
Stars
270
Forks
21
PR merge metrics
No merged PRs in 30d

Description

Hello @nhairs!

The recently published advisory CVE-2025-27607 details a name resurrection attack that is no longer possible (as the name has been reserved by PyPI admins) and was never exploited. This doesn't line up with the CVE severity score of 8.8 which is now causing likely some panic for users who think certain versions of this library are actively exploitable.

I suggest the following:

  • Update the advisory to a CVSS score of 0.0 (this is valid for "informational" advisories)
  • Update the advisory with a note that this is no longer exploitable and no action is required at this time, even for users using "affected" versions named in the advisory.

Happy to answer questions!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the CVE-2025-27607/GHSA-wmxh-pxcx-9w24 advisory and the concerns recorded in this issue. Done means the advisory has a CVSS score of 0.0 and clearly states that the name is reserved, exploitation is no longer possible, and affected users need take no action.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
40/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.