CVE-2025-13836

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Dec 2025, 19:15

Type Values Removed Values Added
CWE CWE-400

02 Dec 2025, 18:15

Type Values Removed Values Added
References
  • () https://mail.python.org/archives/list/[email protected]/thread/OQ6G7MKRQIS3OAREC3HNG3D2DPOU34XO/ -

01 Dec 2025, 19:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/4ce27904b597c77d74dd93f2c912676021a99155 -
  • () https://github.com/python/cpython/commit/5a4c4a033a4a54481be6870aa1896fad732555b5 -

01 Dec 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 18:16

Updated : 2025-12-02 19:15


NVD link : CVE-2025-13836

Mitre link : CVE-2025-13836

CVE.ORG link : CVE-2025-13836


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption