https://seclists.org/oss-sec/2025/q4/251: CPython vulnerable to CVE-2025-13836, CVE-2025-13837, & CVE-2025-12084
Published Dec 5, 2025
·Updated
Affected Software
1 affected component
pypi/cpython
Frequently Asked Questions
1
What is the severity of CVE-2025-13836?
CVE-2025-13836 is classified as a MEDIUM severity vulnerability.
2
How do I fix CVE-2025-13836?
To fix CVE-2025-13836, update your CPython to the latest version that addresses this vulnerability.
3
What type of attack is associated with CVE-2025-13836?
CVE-2025-13836 is associated with an excessive read buffering Denial of Service (DoS) attack in http.client.
4
Which version of CPython is affected by CVE-2025-13836?
CVE-2025-13836 affects specific versions of CPython prior to the patch release.
5
When was CVE-2025-13836 published?
CVE-2025-13836 was published on December 5, 2025.