CVE-2025-13836 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server…
Medium CVSS: 6.3

CVE-2025-13836

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
Vendor
Python
Product
Python
CWE
CWE-400
Yayın Tarihi
2025-12-01 18:16:04
Güncelleme
2026-02-10 19:58:12
Source Identifier
cna@python.org
KEV Date Added
-

Kategoriler

Referanslar