CVE-2025-13837
published 2025-12-01CVE-2025-13837: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.19%
9.1th percentile
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < python3.13 3.13.11-1 (forky) | python3.13 3.13.11-1 (forky) |
| debian | python3.11 | < python3.13 3.13.11-1 (forky) | python3.13 3.13.11-1 (forky) |
| debian | python3.13 | < python3.13 3.13.11-1 (forky) | python3.13 3.13.11-1 (forky) |
| debian | python3.14 | < python3.13 3.13.11-1 (forky) | python3.13 3.13.11-1 (forky) |
| debian | python3.9 | < python3.13 3.13.11-1 (forky) | python3.13 3.13.11-1 (forky) |
| msrc | azl3_python3_3.12.9-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.9-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python3_3.9.19-16_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-17_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-18_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-19_on_cbl_mariner_2.0 | — | — |
| python | python | < 3.13.10 | 3.13.10 |
| python | python | — | — |
| python | python | >= 3.14.0 < 3.14.1 | 3.14.1 |
| python_software_foundation | cpython | < 3.10.20 | 3.10.20 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.15 | 3.11.15 |
| python_software_foundation | cpython | >= 3.12.0 < 3.12.13 | 3.12.13 |
| python_software_foundation | cpython | >= 3.13.0 < 3.13.10 | 3.13.10 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.1 | 3.14.1 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0a3 | 3.15.0a3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv4.02.1LOWCVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.7MEDIUM
vendor_msrc5.5MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python2.7 vulnerabilities
osv·2026-03-19·CVSS 5.7
CVE-2025-12084 [MEDIUM] python2.7 vulnerabilities
python2.7 vulnerabilities
USN-8018-1 fixed CVE-2025-12084, CVE-2025-15282, CVE-2026-0672,
CVE-2026-0865 for python3. This update provides the corresponding updates
for python2.7.
Original advisory details:
Denis Ledoux discovered that Python incorrectly parsed email message
headers. An attacker could possibly use this issue to inject arbitrary
headers into email messages. This issue only affected python3.6,
python3.7, python3.8, python3.9, python3.10, python3.11, python3.12,
python3.13, and python3.14 packages. (CVE-2025-11468)
Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python
inefficiently parsed XML input with quadratic complexity. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2025-12084)
It was discovered that Python incorrectly pars
OSV
python3.4, python3.5, python3.6, python3.7, python3.8, python3.9,
python3.10, python3.11, python3.12, python3.13, python3.14 regression
osv·2026-03-09·CVSS 5.7
CVE-2025-15366 [MEDIUM] python3.4, python3.5, python3.6, python3.7, python3.8, python3.9,
python3.10, python3.11, python3.12, python3.13, python3.14 regression
python3.4, python3.5, python3.6, python3.7, python3.8, python3.9,
python3.10, python3.11, python3.12, python3.13, python3.14 regression
USN-8018-1 fixed vulnerabilities in python3. That update introduced
regressions. The patches for CVE-2025-15366 and CVE-2025-15367 caused
behavior regressions in IMAP and POP3 handling, which upstream chose to
avoid by not backporting them. Additionally, the patch for CVE-2026-0865
incorrectly rejected horizontal tabs in wsgiref headers. This update fixes
these problems.
We apologize for the inconvenience.
Original advisory details:
Denis Ledoux discovered that Python incorrectly parsed email message
headers. An attacker could possibly use this issue to inject arbitrary
headers into email messages. This issue only affected python3.6,
python3.7, python3
OSV
python3.14, python3.13, python3.12, python3.11, python3.10, python3.9,
python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
osv·2026-02-05·CVSS 5.7
CVE-2025-11468 [MEDIUM] python3.14, python3.13, python3.12, python3.11, python3.10, python3.9,
python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
python3.14, python3.13, python3.12, python3.11, python3.10, python3.9,
python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
Denis Ledoux discovered that Python incorrectly parsed email message
headers. An attacker could possibly use this issue to inject arbitrary
headers into email messages. This issue only affected python3.6, python3.7,
python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and
python3.14 packages. (CVE-2025-11468)
Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python
inefficiently parsed XML input with quadratic complexity. An attacker could
possibly use this issue to cause a denial of service. (CVE-2025-12084)
It was discovered that Python incorrectly parsed malicious plist files. An
attacker could possibly use this issue
GHSA
GHSA-qhx6-hpfj-8m4g: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
ghsa_unreviewed·2025-12-01
CVE-2025-13837 [LOW] CWE-400 GHSA-qhx6-hpfj-8m4g: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
OSV
CVE-2025-13837: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
osv·2025-12-01·CVSS 2.1
CVE-2025-13837 [LOW] CVE-2025-13837: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
Ubuntu
Python 2.7 vulnerabilities
vendor_ubuntu·2026-03-19·CVSS 5.3
CVE-2025-12084 [MEDIUM] Python 2.7 vulnerabilities
Title: Python 2.7 vulnerabilities
Summary: Several security issues were fixed in python2.7
USN-8018-1 fixed CVE-2025-12084, CVE-2025-15282, CVE-2026-0672,
CVE-2026-0865 for python3. This update provides the corresponding updates
for python2.7.
Original advisory details:
Denis Ledoux discovered that Python incorrectly parsed email message
headers. An attacker could possibly use this issue to inject arbitrary
headers into email messages. This issue only affected python3.6,
python3.7, python3.8, python3.9, python3.10, python3.11, python3.12,
python3.13, and python3.14 packages. (CVE-2025-11468)
Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python
inefficiently parsed XML input with quadratic complexity. An attacker
could possibly use this issue to cause a denial of service
Ubuntu
Python regression
vendor_ubuntu·2026-03-09·CVSS 5.3
CVE-2025-15367 [MEDIUM] Python regression
Title: Python regression
Summary: USN-8018-1 introduced a regression in Python
USN-8018-1 fixed vulnerabilities in python3. That update introduced
regressions. The patches for CVE-2025-15366 and CVE-2025-15367 caused
behavior regressions in IMAP and POP3 handling, which upstream chose to
avoid by not backporting them. Additionally, the patch for CVE-2026-0865
incorrectly rejected horizontal tabs in wsgiref headers. This update fixes
these problems.
We apologize for the inconvenience.
Original advisory details:
Denis Ledoux discovered that Python incorrectly parsed email message
headers. An attacker could possibly use this issue to inject arbitrary
headers into email messages. This issue only affected python3.6,
python3.7, python3.8, python3.9, python3.10, python3.11, python3.12,
pytho
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-02-05·CVSS 5.3
CVE-2025-15366 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
Denis Ledoux discovered that Python incorrectly parsed email message
headers. An attacker could possibly use this issue to inject arbitrary
headers into email messages. This issue only affected python3.6, python3.7,
python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and
python3.14 packages. (CVE-2025-11468)
Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python
inefficiently parsed XML input with quadratic complexity. An attacker could
possibly use this issue to cause a denial of service. (CVE-2025-12084)
It was discovered that Python incorrectly parsed malicious plist files. An
attacker could possibly use this issue to cause Python to use excessive
resources, leading to
Microsoft
Out-of-memory when loading Plist
vendor_msrc·2025-12-09·CVSS 5.5
CVE-2025-13837 [LOW] CWE-400 Out-of-memory when loading Plist
Out-of-memory when loading Plist
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
cpython: Out-of-memory when loading Plist
vendor_redhat·2025-12-01·CVSS 2.1
CVE-2025-13837 [LOW] CWE-770 cpython: Out-of-memory when loading Plist
cpython: Out-of-memory when loading Plist
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
A flaw was found in the plistlib module in the Python standard library. The amount of data to read from a Plist file is specified in the file itself. This issue allows a specially crafted Plist file to cause an application to allocate a large amount of memory, potentially resulting in allocations errors, swapping, out-of-memory conditions or even system freezes.
Statement: This issue can only be exploited by Python applications processing malicious or untrusted Plist files, which are not typically done in Linux systems or applications. Furthermore, this flaw can cause only a denial of service with
Debian
CVE-2025-13837: pypy3 - When loading a plist file, the plistlib module reads data in size specified by t...
vendor_debian·2025·CVSS 2.1
CVE-2025-13837 [LOW] CVE-2025-13837: pypy3 - When loading a plist file, the plistlib module reads data in size specified by t...
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2bhttps://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1bahttps://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cbhttps://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111https://github.com/python/cpython/issues/119342https://github.com/python/cpython/pull/119343https://mail.python.org/archives/list/[email protected]/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/
2025-12-01
Published