CVE-2025-71176: Medium severity pypi/pytest vulnerability
Published Jan 22, 2026
·Updated
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
Affected Software
3 affected componentsFixes available
pypi/pytest<=9.0.2
IBM Db2 Genius Hub<=1.1, 1.1.1, 1.1.2
IBM Agentics<=1.0
Event History
Jan 22, 2026
CVE Published
via MITRE·04:59 AM
Data Sourced
via MITRE·04:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeakness
Jul 13, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71176?
CVE-2025-71176 has been classified as a critical vulnerability due to its potential for denial of service and privilege escalation.
2
How do I fix CVE-2025-71176?
To mitigate CVE-2025-71176, update pytest to version 9.1.0 or higher.
3
Who is affected by CVE-2025-71176?
All UNIX systems using pytest version 9.0.2 or earlier are affected by CVE-2025-71176.
4
What types of attacks can CVE-2025-71176 facilitate?
CVE-2025-71176 can allow local users to cause denial of service or potentially gain elevated privileges.
5
Is there any workaround for CVE-2025-71176?
As a temporary workaround for CVE-2025-71176, avoid using pytest in environments where untrusted users have access.