CVE-2025-13836EPSS p75.4%
CVE-2025-13836CVE-2025-13836
python / python
Description
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 1.63% probability of exploitation · percentile 75.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-03 |