THREAT OPS › Threat News › [NVD] CVE-2025-13836 (HIGH 7.5) — When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
[NVD] CVE-2025-13836 (HIGH 7.5) — When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
CVE-2025-13836 CVSS: 7.5 HIGH Published: 2025-12-01T18:16:04.200
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
Indicators of compromise
- CVE-2025-13836cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13836