Skip to main content

CVE-2025-13836

7.5
HIGHCVSS v3.1 Base Score
0.21%
LOW RiskEPSS (44th percentile)

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

Published: 12/1/2025
Modified: 5/18/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Score (Exploitation Probability)

0.21%LOW Exploitation Risk
44th percentile

This vulnerability has a 0.21% probability of being exploited in the next 30 days, ranking higher than 44% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-400)

Similar SeverityHIGH