Palo Alto Vulnerability Report
HighPublished Dec 18, 2025 · updated Dec 26, 2025
### Impact Vendor Palo Alto Networks ### Affected Product PA-54xx All supported versions of PAN-OS. Tested: PAN-OS 10.x - 10.2.16-h1 PAN-OS 11x - 11.2.1 ### Important Dates The report was officially received by Palo Alto Networks PSIRT on Aug 25, 2025. The standard 90-day disclosure period concluded on Nov 23, 2025. Public release of the full details is scheduled for mid 2026, following an exception to our policy granted at the request of Palo Alto PSIRT, citing the complexity of the required fix and the need for additional time to deploy a patch. Palo Alto will have the beta release fix ready by March 30, 2026.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| security-research Product | < TBD | TBD |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 22 | Python Wheel (Zip) Parser Differential Vulnerability v2.0 | Medium | 0.9.6 |
| Jan 6 | TrustZone Break-in Vulnerabilities in Ampere UEFI MM Drivers (Buffer Overflow and Stack Information Leak) | Medium4.6 | 3.5.9.3+2 more |
| Jan 6 | TrustZone Break-in Vulnerabilities in Ampere UEFI MM Drivers (Arbitrary Out-of-Bounds Write) | Medium4.6 | 3.5.9.3+2 more |
| Dec 152025 | Token Leak via Open Redirection and CSRF in the Callback Handler of cloudflare/workers-oauth-provider | Medium | v0.0.12 |
| Nov 182025 | "Astral-tokio-tar" / "uv" Arbitrary Write Path Traversal Vulnerability | Medium | 0.8.22 |
| Oct 272025 | Python - Zip64 Locator Offset Vulnerability | Medium | No fix yet |