Back to Database
Status published
Low
CVE-2025-13837
Out-of-memory when loading Plist
Vulnerability Description
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13837
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/python/cpython/pull/119343
- https://github.com/python/cpython/issues/119342
- https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70
- https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba
- https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb
- https://mail.python.org/archives/list/security-announce@python.org/thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/
- https://github.com/python/cpython/commit/5a8b19677d818fb41ee55f310233772e15aa1a2b
- https://github.com/python/cpython/commit/568342cfc8f002d9a15f30238f26b9d2e0e79036
- https://github.com/python/cpython/commit/cefee7d118a26ef6cd43db59bb9d98ca9a331111
More from Python Software Foundation
View All →CVE-2025-8291
ZIP64 End of Central Directory (EOCD) Locator record offset not checked
Medium
4.3
CVE-2025-8194
Tarfile infinite loop during parsing with negative member offset
High
7.5
CVE-2025-6075
Quadratic complexity in os.path.expandvars() with user-controlled template
Low
1.8
CVE-2025-6069
HTMLParser quadratic complexity when processing malformed inputs
Medium
4.3
CVE-2025-4517
Arbitrary writes via tarfile realpath overflow
Critical
9.4
Affected Vendor
Python Software Foundation
View all reports →Affected Software
CPython
Vulnerable Versions:
0, 3.11.0, 3.12.0, 3.13.0, 3.14.0, 3.15.0a1
Timeline
Official Publish:
December 1st, 2025
Last Modified:
March 3rd, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.