CVE-2025-13837Uncontrolled Resource Consumption in Software Foundation Cpython

Severity
2.1LOWNVD
EPSS
0.0%
top 89.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1
Latest updateFeb 5

Description

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N

Affected Packages2 packages

NVDpython/python3.14.03.14.1+2
CVEListV5python_software_foundation/cpython3.11.03.11.15+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qhx6-hpfj-8m4g: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues2025-12-01
CVEList
Out-of-memory when loading Plist2025-12-01
OSV
CVE-2025-13837: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues2025-12-01

📋Vendor Advisories

4
Ubuntu
Python vulnerabilities2026-02-05
Microsoft
Out-of-memory when loading Plist2025-12-09
Red Hat
cpython: Out-of-memory when loading Plist2025-12-01
Debian
CVE-2025-13837: pypy3 - When loading a plist file, the plistlib module reads data in size specified by t...2025

💬Community

1
Bugzilla
CVE-2025-13837 cpython: Out-of-memory when loading Plist2025-12-01
CVE-2025-13837 — Uncontrolled Resource Consumption | cvebase