Junglewise Threat Intelligence

CVE-2025-13836: Python http.client denial of service via large Content-Length header

CVE-2025-13836 · Severity: high · CVSS 7.5 · Published 2025-12-01

Technologies: Python Software Foundation CPython. Vendors: Python Software Foundation.

Executive brief

A vulnerability in Python's standard HTTP client library could allow a malicious server to crash a Python-based application. By sending a specially crafted response header with an extremely large size value, the server can force the Python application to exhaust its available memory. This results in a denial-of-service (DoS) condition where the application stops functioning or the entire system becomes unresponsive.

Technical details

A vulnerability exists in the `http.client.HTTPResponse.read()` method of Python's standard library. When the method is called without a specific read amount, it defaults to allocating memory based on the value provided in the 'Content-Length' HTTP header before actually receiving the data from the socket. A malicious server can exploit this by sending a response with an arbitrarily large Content-Length header, causing the client to attempt a massive memory allocation. This leads to uncontrolled resource consumption (CWE-400), resulting in an Out-of-Memory (OOM) error or system swapping, even if the server never sends the actual data. The issue has been addressed by modifying the client to read data in chunks rather than pre-allocating the entire length.

Affected products

  • Python Software Foundation Python up to (excluding) 3.10.20, 3.11.0 to (excluding) 3.11.15, 3.12.0 to (excluding) 3.12.13, 3.13.0 to (excluding) 3.13.11, 3.14.0, 3.15.0 alpha 1-2

Timeline

  • 2024-05-23: disclosed: Issue opened on GitHub repository
  • 2025-12-01: advisory: CVE published and patches released

References