CVE-2025-13836

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.14.0:-:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-01 18:16

Updated : 2026-01-26 15:16


NVD link : CVE-2025-13836

Mitre link : CVE-2025-13836

CVE.ORG link : CVE-2025-13836


JSON object : View

Products Affected

python

  • python
CWE
CWE-125

Out-of-bounds Read

CWE-400

Uncontrolled Resource Consumption