UBUNTU-CVE-2025-13836

Source
https://ubuntu.com/security/CVE-2025-13836
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-13836
Upstream
Downstream
Related
Published
2025-12-01T18:16:00Z
Modified
2026-01-20T18:15:16.611434Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L CVSS Calculator
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

References

Affected packages

Ubuntu:22.04:LTS

python3.10

Package

Name
python3.10
Purl
pkg:deb/ubuntu/python3.10@3.10.12-1~22.04.13?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.12-1~22.04.13

Affected versions

3.*

3.10.0-2
3.10.0-3
3.10.0-4
3.10.0-5
3.10.0-5build1
3.10.1-1
3.10.1-2
3.10.2-1
3.10.2-5
3.10.2-7
3.10.3-1
3.10.4-3
3.10.4-3ubuntu0.1
3.10.6-1~22.04
3.10.6-1~22.04.1
3.10.6-1~22.04.2
3.10.6-1~22.04.2ubuntu1
3.10.6-1~22.04.2ubuntu1.1
3.10.12-1~22.04.2
3.10.12-1~22.04.3
3.10.12-1~22.04.4
3.10.12-1~22.04.5
3.10.12-1~22.04.6
3.10.12-1~22.04.7
3.10.12-1~22.04.8
3.10.12-1~22.04.9
3.10.12-1~22.04.10
3.10.12-1~22.04.11
3.10.12-1~22.04.12

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.10",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "libpython3.10",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "libpython3.10-dev",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "libpython3.10-minimal",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "libpython3.10-stdlib",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "libpython3.10-testsuite",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10-dev",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10-examples",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10-full",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10-minimal",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10-nopie",
            "binary_version": "3.10.12-1~22.04.13"
        },
        {
            "binary_name": "python3.10-venv",
            "binary_version": "3.10.12-1~22.04.13"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

Ubuntu:24.04:LTS

python3.12

Package

Name
python3.12
Purl
pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.10?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.12.3-1ubuntu0.10

Affected versions

3.*

3.12.0-1
3.12.0-5
3.12.0-6
3.12.0-7
3.12.1-2
3.12.2-1
3.12.2-4build3
3.12.2-4build4
3.12.2-5ubuntu3
3.12.3-1
3.12.3-1ubuntu0.1
3.12.3-1ubuntu0.2
3.12.3-1ubuntu0.3
3.12.3-1ubuntu0.4
3.12.3-1ubuntu0.5
3.12.3-1ubuntu0.6
3.12.3-1ubuntu0.7
3.12.3-1ubuntu0.8
3.12.3-1ubuntu0.9

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.12",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "libpython3.12-dev",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "libpython3.12-minimal",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "libpython3.12-stdlib",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "libpython3.12-testsuite",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "libpython3.12t64",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12-dev",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12-examples",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12-full",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12-minimal",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12-nopie",
            "binary_version": "3.12.3-1ubuntu0.10"
        },
        {
            "binary_name": "python3.12-venv",
            "binary_version": "3.12.3-1ubuntu0.10"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

Ubuntu:25.10

python3.13

Package

Name
python3.13
Purl
pkg:deb/ubuntu/python3.13@3.13.7-1ubuntu0.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.7-1ubuntu0.2

Affected versions

3.*

3.13.3-1
3.13.3-2
3.13.3-4
3.13.4-1
3.13.5-1
3.13.5-2
3.13.6-1
3.13.7-1
3.13.7-1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.13",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "libpython3.13",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "libpython3.13-dev",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "libpython3.13-minimal",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "libpython3.13-stdlib",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "libpython3.13-testsuite",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-dev",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-examples",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-full",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-gdbm",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-minimal",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-nopie",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-tk",
            "binary_version": "3.13.7-1ubuntu0.2"
        },
        {
            "binary_name": "python3.13-venv",
            "binary_version": "3.13.7-1ubuntu0.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

python3.14

Package

Name
python3.14
Purl
pkg:deb/ubuntu/python3.14@3.14.0-1ubuntu0.1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.14.0-1ubuntu0.1

Affected versions

3.*

3.14.0~a7-0ubuntu1
3.14.0~b1-1
3.14.0~b3-1
3.14.0~rc1-1
3.14.0~rc2-1
3.14.0~rc3-1
3.14.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.14",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "libpython3.14",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "libpython3.14-dev",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "libpython3.14-minimal",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "libpython3.14-stdlib",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "libpython3.14-testsuite",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-dev",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-examples",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-full",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-gdbm",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-minimal",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-nopie",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-tk",
            "binary_version": "3.14.0-1ubuntu0.1"
        },
        {
            "binary_name": "python3.14-venv",
            "binary_version": "3.14.0-1ubuntu0.1"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

Ubuntu:Pro:18.04:LTS

python3.8

Package

Name
python3.8
Purl
pkg:deb/ubuntu/python3.8@3.8.0-3ubuntu1~18.04.2+esm8?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.0-3ubuntu1~18.04.2+esm8

Affected versions

3.*

3.8.0-3~18.04
3.8.0-3~18.04.1
3.8.0-3ubuntu1~18.04.2
3.8.0-3ubuntu1~18.04.2+esm1
3.8.0-3ubuntu1~18.04.2+esm2
3.8.0-3ubuntu1~18.04.2+esm3
3.8.0-3ubuntu1~18.04.2+esm4
3.8.0-3ubuntu1~18.04.2+esm5
3.8.0-3ubuntu1~18.04.2+esm6
3.8.0-3ubuntu1~18.04.2+esm7

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.8",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "libpython3.8",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "libpython3.8-dev",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "libpython3.8-minimal",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "libpython3.8-stdlib",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "libpython3.8-testsuite",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "python3.8",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "python3.8-dev",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "python3.8-examples",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "python3.8-minimal",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        },
        {
            "binary_name": "python3.8-venv",
            "binary_version": "3.8.0-3ubuntu1~18.04.2+esm8"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

Ubuntu:Pro:20.04:LTS

python3.8

Package

Name
python3.8
Purl
pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04.18+esm4?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.10-0ubuntu1~20.04.18+esm4

Affected versions

3.*

3.8.0-1
3.8.0-2
3.8.0-3
3.8.0-4
3.8.0-5
3.8.1-2ubuntu3
3.8.2~rc1-1ubuntu1
3.8.2-1
3.8.2-1ubuntu1
3.8.2-1ubuntu1.1
3.8.2-1ubuntu1.2
3.8.5-1~20.04
3.8.5-1~20.04.2
3.8.5-1~20.04.3
3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.7
3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.9
3.8.10-0ubuntu1~20.04.10
3.8.10-0ubuntu1~20.04.11
3.8.10-0ubuntu1~20.04.12
3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.14
3.8.10-0ubuntu1~20.04.15
3.8.10-0ubuntu1~20.04.16
3.8.10-0ubuntu1~20.04.17
3.8.10-0ubuntu1~20.04.18
3.8.10-0ubuntu1~20.04.18+esm1
3.8.10-0ubuntu1~20.04.18+esm2
3.8.10-0ubuntu1~20.04.18+esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.8",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "libpython3.8",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "libpython3.8-dev",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "libpython3.8-minimal",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "libpython3.8-stdlib",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "libpython3.8-testsuite",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "python3.8",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "python3.8-dev",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "python3.8-examples",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "python3.8-full",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "python3.8-minimal",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        },
        {
            "binary_name": "python3.8-venv",
            "binary_version": "3.8.10-0ubuntu1~20.04.18+esm4"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

python3.9

Package

Name
python3.9
Purl
pkg:deb/ubuntu/python3.9@3.9.5-3ubuntu0~20.04.1+esm8?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.5-3ubuntu0~20.04.1+esm8

Affected versions

3.*

3.9.0~rc1-1~20.04
3.9.0-5~20.04
3.9.5-3~20.04.1
3.9.5-3ubuntu0~20.04.1
3.9.5-3ubuntu0~20.04.1+esm1
3.9.5-3ubuntu0~20.04.1+esm2
3.9.5-3ubuntu0~20.04.1+esm3
3.9.5-3ubuntu0~20.04.1+esm4
3.9.5-3ubuntu0~20.04.1+esm5
3.9.5-3ubuntu0~20.04.1+esm6
3.9.5-3ubuntu0~20.04.1+esm7

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.9",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "libpython3.9",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "libpython3.9-dev",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "libpython3.9-minimal",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "libpython3.9-stdlib",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "libpython3.9-testsuite",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "python3.9",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "python3.9-dev",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "python3.9-examples",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "python3.9-full",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "python3.9-minimal",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        },
        {
            "binary_name": "python3.9-venv",
            "binary_version": "3.9.5-3ubuntu0~20.04.1+esm8"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"

Ubuntu:Pro:22.04:LTS

python3.11

Package

Name
python3.11
Purl
pkg:deb/ubuntu/python3.11@3.11.0~rc1-1~22.04.1~esm7?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.11.0~rc1-1~22.04.1~esm7

Affected versions

3.*

3.11.0~rc1-1~22.04
3.11.0~rc1-1~22.04.1~esm1
3.11.0~rc1-1~22.04.1~esm2
3.11.0~rc1-1~22.04.1~esm3
3.11.0~rc1-1~22.04.1~esm4
3.11.0~rc1-1~22.04.1~esm5
3.11.0~rc1-1~22.04.1~esm6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "idle-python3.11",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "libpython3.11",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "libpython3.11-dev",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "libpython3.11-minimal",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "libpython3.11-stdlib",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "libpython3.11-testsuite",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11-dev",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11-examples",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11-full",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11-minimal",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11-nopie",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        },
        {
            "binary_name": "python3.11-venv",
            "binary_version": "3.11.0~rc1-1~22.04.1~esm7"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-13836.json"