If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
The vulnerability was already fixed in all active branches, but the fixes are waiting to be released (except 3.9 and 3.15): https://github.com/python/cpython/issues/136065
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:23530 https://access.redhat.com/errata/RHSA-2025:23530
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23342 https://access.redhat.com/errata/RHSA-2025:23342