CVE-2013-1753: Python

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

Affected products

  • Python Python: from 2.7.0, before 2.7.9 (fixed in 2.7.9); from 3.2.0, before 3.2.6 (fixed in 3.2.6); from 3.3.0, before 3.3.6 (fixed in 3.3.6); from 3.4.0, before 3.4.3 (fixed in 3.4.3)

Published 2020-03-11. Last modified 2026-06-16.