When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
CVSS
No CVSS.
References
Configurations
No configuration.
History
02 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-400 |
02 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Dec 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 18:16
Updated : 2025-12-02 19:15
NVD link : CVE-2025-13836
Mitre link : CVE-2025-13836
CVE.ORG link : CVE-2025-13836
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
