PT-2026-56871 · Python+1 · Python+1

·

CVE-2026-15308

·

Published

2026-07-09

·

Updated

2026-09-10

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CPython (affected versions not specified)
Description The incremental HTML parser html.parser.HTMLParser contains an issue that allows for CPU denial-of-service when processing uncontrolled data. The root cause is improper input handling that leads to pathological parsing behavior, specifically algorithmic complexity and resource exhaustion, when markup declarations are repeatedly left unterminated. An attacker can exploit this by providing crafted HTML to any service or pipeline using HTMLParser, which can result in CPU core exhaustion and the degradation or complete failure of affected applications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:39183
ALSA-2026:39320
ALSA-2026:39771
ALSA-2026:39798
ALSA-2026:39893
ALSA-2026:40856
ALSA-2026:41949
AZL-92271
BIT-LIBPYTHON-2026-15308
BIT-PYTHON-2026-15308
BIT-PYTHON-MIN-2026-15308
CVE-2026-15308
ECHO-DDD3-D328-2DB3
OESA-2026-3180
OESA-2026-3181
OESA-2026-3182
OPENSUSE-SU-2026:11426-1
OPENSUSE-SU-2026:11427-1
OPENSUSE-SU-2026:11428-1
OPENSUSE-SU-2026:11429-1
OPENSUSE-SU-2026:11534-1
OPENSUSE-SU-2026:11597-1
OPENSUSE-SU-2026:21595-1
PSF-2026-33
RHSA-2026:37533
RHSA-2026:37535
RHSA-2026:39183
RHSA-2026:39320
RHSA-2026:39771
RHSA-2026:39798
RHSA-2026:39893
RHSA-2026:40856
RHSA-2026:41949
RHSA-2026:47939
RHSA-2026:50064
RHSA-2026:50065
RHSA-2026:50770
RHSA-2026:50771
RHSA-2026:50816
SUSE-SU-2026:23159-1
SUSE-SU-2026:23191-1
SUSE-SU-2026:23212-1
SUSE-SU-2026:23303-1
SUSE-SU-2026:3530-1
SUSE-SU-2026:3548-1
SUSE-SU-2026:3560-1
SUSE-SU-2026:3569-1
SUSE-SU-2026:3601-1
SUSE-SU-2026:3635-1
SUSE-SU-2026:3649-1
SUSE-SU-2026:3855-1
SUSE-SU-2026:3862-1
USN-8744-1

Affected Products

Python
Rocky Linux