The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.
References
Configurations
History
10 Jul 2026, 20:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 - Patch | |
| References | () https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced - Patch | |
| References | () https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606 - Patch | |
| References | () https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd - Patch | |
| References | () https://github.com/python/cpython/issues/153030 - Patch | |
| References | () https://github.com/python/cpython/pull/153031 - Issue Tracking, Patch | |
| References | () https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/ - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2026/07/09/4 - Third Party Advisory | |
| CPE | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | |
| First Time |
Python
Python python |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | NVD-CWE-noinfo |
09 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 17:16
Updated : 2026-07-23 19:16
NVD link : CVE-2026-15308
Mitre link : CVE-2026-15308
CVE.ORG link : CVE-2026-15308
JSON object : View
Products Affected
python
- python
CWE
