CVE-2026-15308

Published: July 10, 2026Last modified: July 14, 2026

Description

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpython3Fixed (3.11.15-r6)
25 LTSpython3Fixed (3.12.13-r6)
Streampython3Fixed (3.14.5-r5)
Hardened Containers23 LTSpython3Fixed (3.11.15-r6)
25 LTSpython3Fixed (3.12.13-r6)
Streampython3Fixed (3.14.5-r5)

References

ON THIS PAGE