7.5

CVE-2026-15308

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version < 3.10.21
Python ≫ Python Version >= 3.11.0 < 3.11.16
Python ≫ Python Version >= 3.12.0 < 3.12.14
Python ≫ Python Version >= 3.13.0 < 3.13.15
Python ≫ Python Version >= 3.14.0 < 3.14.7
Python ≫ Python Version 3.15.0 Update alpha1
Python ≫ Python Version 3.15.0 Update alpha2
Python ≫ Python Version 3.15.0 Update alpha3
Python ≫ Python Version 3.15.0 Update alpha4
Python ≫ Python Version 3.15.0 Update alpha5
Python ≫ Python Version 3.15.0 Update alpha6
Python ≫ Python Version 3.15.0 Update alpha7
Python ≫ Python Version 3.15.0 Update alpha8
Python ≫ Python Version 3.15.0 Update beta1
Python ≫ Python Version 3.15.0 Update beta2
Python ≫ Python Version 3.15.0 Update beta3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.472
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@python.org 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/python/cpython/issues/153030
Patch
https://github.com/python/cpython/pull/153031
Patch
Issue Tracking
https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/
Mailing List
https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9
Patch
https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced
Patch
https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606
Patch
https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd
Patch
http://www.openwall.com/lists/oss-security/2026/07/09/4
Third Party Advisory
https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14
Patch
https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7
Patch
https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00
Patch