CVE-2025-13837: Python

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

Affected products

  • Python Python: before 3.13.10 (fixed in 3.13.10); from 3.14.0, before 3.14.1 (fixed in 3.14.1); version 3.15.0 only

Published 2025-12-01. Last modified 2026-09-03.