Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-13836

Опубликовано: 01 дек. 2025
Источник: debian
EPSS Низкий

Описание

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.2-1package
python3.13fixed3.13.11-1package
python3.13fixed3.13.5-2+deb13u1trixiepackage
python3.11removedpackage
python3.11fixed3.11.2-6+deb12u7bookwormpackage
python3.9removedpackage
pypy3fixed7.3.21+dfsg-1package
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3not-affectedbullseyepackage

Примечания

  • https://github.com/python/cpython/issues/119451

  • https://github.com/python/cpython/pull/119454

  • https://github.com/python/cpython/commit/5a4c4a033a4a54481be6870aa1896fad732555b5 (main)

  • https://github.com/python/cpython/commit/4ce27904b597c77d74dd93f2c912676021a99155 (v3.14.1)

  • https://github.com/python/cpython/commit/289f29b0fe38baf2d7cb5854f4bb573cc34a6a15 (v3.13.11)

  • https://github.com/python/cpython/commit/afc40bdd3dd71f343fd9016f6d8eebbacbd6587c (v3.11.15)

  • Introduced by: https://github.com/python/cpython/commit/d6bf6f2d0c83f0c64ce86e7b9340278627798090 (v3.8.0a4)

  • but reverted for branch 3.9 (only): https://github.com/python/cpython/commit/153365d864c411f6fb523efa752ccb3497d815ca (v3.9.7)

EPSS

Процентиль: 72%
0.01525
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

CVSS3: 6.8
redhat
8 месяцев назад

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

CVSS3: 7.5
nvd
8 месяцев назад

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

msrc
8 месяцев назад

Excessive read buffering DoS in http.client

rocky
6 месяцев назад

Moderate: python3.12 security update

EPSS

Процентиль: 72%
0.01525
Низкий