« Volver al listado

CVE-2025-13836

Estado: AnalizadaMedia (6.3)—

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-13836",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-13836",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-01T18:32:37.506031Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@python.org",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "LOW",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@python.org",
      "affectedData": [
        {
          "repo": "https://github.com/python/cpython",
          "vendor": "Python Software Foundation",
          "modules": [
            "http.client"
          ],
          "product": "CPython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.10.20",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.15",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.13",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.13.0",
              "lessThan": "3.13.11",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.14.0",
              "lessThan": "3.14.1",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.15.0a1",
              "lessThan": "3.15.0a3",
              "versionType": "python"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-12-01T18:16:04.200",
  "references": [
    {
      "url": "https://github.com/python/cpython/commit/14b1fdb0a94b96f86fc7b86671ea9582b8676628",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/289f29b0fe38baf2d7cb5854f4bb573cc34a6a15",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/4ce27904b597c77d74dd93f2c912676021a99155",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/5a4c4a033a4a54481be6870aa1896fad732555b5",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/5dc101675fd22918facbbe0fecdc821502beaaf0",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/afc40bdd3dd71f343fd9016f6d8eebbacbd6587c",
      "tags": [
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/issues/119451",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/pull/119454",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "cna@python.org"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/OQ6G7MKRQIS3OAREC3HNG3D2DPOU34XO/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@python.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS."
    },
    {
      "lang": "es",
      "value": "Al leer una respuesta HTTP de un servidor, si no se especifica una cantidad de lectura, el comportamiento predeterminado será usar Content-Length. Esto permite a un servidor malicioso hacer que el cliente lea grandes cantidades de datos en la memoria, lo que podría causar OOM u otro DoS."
    }
  ],
  "lastModified": "2026-09-03T03:15:20.653",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F853468-5391-4279-B369-E480A2B91D6C",
              "versionEndExcluding": "3.10.20"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B38F8DA-DD8F-4887-AC85-CE843E21AD74",
              "versionEndExcluding": "3.11.15",
              "versionStartIncluding": "3.11.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "963DB620-5766-4093-A80B-03F7975F712B",
              "versionEndExcluding": "3.12.13",
              "versionStartIncluding": "3.12.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7FE4D2F0-2F91-4444-87E4-F9231694D429",
              "versionEndExcluding": "3.13.11",
              "versionStartIncluding": "3.13.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.14.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9A884CF-F98D-490D-A3B6-74F0DBFC3BD3"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3327507-0B1D-4F28-A983-D07A2C8A7696"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8AF17F1-A27F-4C98-BA5A-B4319710E8D1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@python.org"
}