THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-13836 (HIGH 7.5) — When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

[NVD] CVE-2025-13836 (HIGH 7.5) — When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

lownvdPublished 2025-12-01

CVE-2025-13836 CVSS: 7.5 HIGH Published: 2025-12-01T18:16:04.200

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13836