CVE-2025-13836: Vulnerability in Python Software Foundation CPython
CVE-2025-13836 is a medium severity vulnerability in the Python Software Foundation's CPython implementation. When reading HTTP responses without specifying a read amount, the client defaults to using the Content-Length header. A malicious server can exploit this behavior to cause the client to read excessive data into memory, potentially leading to out-of-memory (OOM) conditions or denial of service (DoS). This affects multiple CPython versions from 0 through 3.15.0a1. There are no known exploits in the wild and no patch or official remediation information is currently available.
AI Analysis
Technical Summary
This vulnerability arises from CPython's HTTP response handling where, if no explicit read amount is specified, the client uses the Content-Length header to determine how much data to read. A malicious server can specify a large Content-Length value, causing the client to allocate and read large amounts of data into memory. This can result in resource exhaustion, specifically out-of-memory conditions or denial of service. The issue affects CPython versions 0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, and 3.15.0a1. The CVSS 4.0 base score is 6.3, indicating medium severity. No patch or vendor advisory detailing remediation is currently provided.
Potential Impact
An attacker controlling a malicious HTTP server can cause a CPython client to consume excessive memory by specifying a large Content-Length header in the HTTP response. This can lead to out-of-memory conditions or denial of service on the client system. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the Python Software Foundation advisory for current remediation guidance. Until a patch is available, users should consider limiting exposure to untrusted HTTP servers or implementing application-level safeguards to restrict memory usage when processing HTTP responses.
CVE-2025-13836: Vulnerability in Python Software Foundation CPython
Description
CVE-2025-13836 is a medium severity vulnerability in the Python Software Foundation's CPython implementation. When reading HTTP responses without specifying a read amount, the client defaults to using the Content-Length header. A malicious server can exploit this behavior to cause the client to read excessive data into memory, potentially leading to out-of-memory (OOM) conditions or denial of service (DoS). This affects multiple CPython versions from 0 through 3.15.0a1. There are no known exploits in the wild and no patch or official remediation information is currently available.
CVSS v4.0
Score 6.3medium
Affected software
pkg:github/python/cpythonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from CPython's HTTP response handling where, if no explicit read amount is specified, the client uses the Content-Length header to determine how much data to read. A malicious server can specify a large Content-Length value, causing the client to allocate and read large amounts of data into memory. This can result in resource exhaustion, specifically out-of-memory conditions or denial of service. The issue affects CPython versions 0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, and 3.15.0a1. The CVSS 4.0 base score is 6.3, indicating medium severity. No patch or vendor advisory detailing remediation is currently provided.
Potential Impact
An attacker controlling a malicious HTTP server can cause a CPython client to consume excessive memory by specifying a large Content-Length header in the HTTP response. This can lead to out-of-memory conditions or denial of service on the client system. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the Python Software Foundation advisory for current remediation guidance. Until a patch is available, users should consider limiting exposure to untrusted HTTP servers or implementing application-level safeguards to restrict memory usage when processing HTTP responses.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PSF
- Date Reserved
- 2025-12-01T17:54:40.759Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 692ddb371fcc71981e81acee
Added to database: 12/01/2025, 18:15:19 UTC
Last enriched: 05/28/2026, 21:24:29 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 853
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.