CVE-2025-13837

Severity CVSS v4.0:
LOW
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
01/12/2025
Last modified:
15/01/2026

Description

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.13.10 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.14.0 (including) 3.14.1 (excluding)
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*