Skip to content

CVE-2025-13836: debian package libpython3.13-stdlib-3.13.5-2 #344

@github-actions

Description

@github-actions

Title

cpython: Excessive read buffering DoS in http.client

Description

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

Severity

HIGH

Fixed in Version

No known fix at this time

Primary URL

https://avd.aquasec.com/nvd/cve-2025-13836

Additional Information

Vulnerability ID: CVE-2025-13836}
Package Name: libpython3.13-stdlib
Package Version: 3.13.5-2

References

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions