PT-2026-56871 · Python+1 · Python+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CPython (affected versions not specified)
Description
The incremental HTML parser
html.parser.HTMLParser contains an issue that allows for CPU denial-of-service when processing uncontrolled data. The root cause is improper input handling that leads to pathological parsing behavior, specifically algorithmic complexity and resource exhaustion, when markup declarations are repeatedly left unterminated. An attacker can exploit this by providing crafted HTML to any service or pipeline using HTMLParser, which can result in CPU core exhaustion and the degradation or complete failure of affected applications.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python
Rocky Linux