CVE-2025-13836: Python

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

Affected products

  • Python Python: before 3.10.20 (fixed in 3.10.20); from 3.11.0, before 3.11.15 (fixed in 3.11.15); from 3.12.0, before 3.12.13 (fixed in 3.12.13); from 3.13.0, before 3.13.11 (fixed in 3.13.11); version 3.14.0 only; version 3.15.0 only

Published 2025-12-01. Last modified 2026-09-03.