PT-2025-48536 · Python+5 · Python+5

Serhiy Storchaka

+1

·

Published

2024-05-21

·

Updated

2026-05-19

·

CVE-2025-13837

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions python3.9 python3.11 python3.13
Description The plistlib module does not properly validate the size of plist files during loading. A malicious plist file can specify a size that causes the module to attempt to allocate an excessive amount of memory, leading to an out-of-memory (OOM) condition and potential denial-of-service (DoS) issues.
Recommendations For python3.9, avoid loading plist files from untrusted sources. For python3.11, avoid loading plist files from untrusted sources. For python3.13, avoid loading plist files from untrusted sources.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:10950
ALSA-2026:19064
ALSA-2026:19177
AZL-71267
AZL-71275
BDU:2026-05126
BIT-LIBPYTHON-2025-13837
BIT-PYTHON-2025-13837
BIT-PYTHON-MIN-2025-13837
CVE-2025-13837
ECHO-8BC4-4724-22D3
MGASA-2025-0324
OESA-2026-1052
OESA-2026-1053
OESA-2026-1054
OESA-2026-1055
OESA-2026-1056
OESA-2026-1057
OPENSUSE-SU-2025:15839-1
OPENSUSE-SU-2025:15840-1
OPENSUSE-SU-2025:15846-1
OPENSUSE-SU-2025:15849-1
OPENSUSE-SU-2025:15850-1
OPENSUSE-SU-2025:15851-1
OPENSUSE-SU-2026:10011-1
OPENSUSE-SU-2026:20081-1
PSF-2025-15
RHSA-2026:10950
RHSA-2026:19064
RHSA-2026:19177
RHSA-2026:7443
RHSA-2026:7661
RHSA-2026:8822
RHSA-2026:8824
SUSE-SU-2025:4522-1
SUSE-SU-2025:4538-1
SUSE-SU-2025:4539-1
SUSE-SU-2026:0024-1
SUSE-SU-2026:0025-1
SUSE-SU-2026:0027-1
SUSE-SU-2026:0130-1
SUSE-SU-2026:0299-1
SUSE-SU-2026:0314-1
SUSE-SU-2026:1062-1
SUSE-SU-2026:1107-1
SUSE-SU-2026:1117-1
SUSE-SU-2026:1349-1
SUSE-SU-2026:20047-1
SUSE-SU-2026:20125-1
SUSE-SU-2026:20154-1
SUSE-SU-2026:20374-1
SUSE-SU-2026:20768-1
SUSE-SU-2026:20796-1
USN-8018-1

Affected Products

Debian
Linuxmint
Python
Red Os
Rocky Linux
Ubuntu