CVE-2026-15308

Severity CVSS v4.0:
HIGH
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
09/07/2026
Last modified:
20/08/2026

Description

The incremental HTML parser (html.parser.HTMLParser) allows for CPU<br /> denial-of-service through repeated unterminated markup declarations when<br /> processing uncontrolled data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.10.21 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.11.0 (including) 3.11.16 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.12.0 (including) 3.12.14 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.13.0 (including) 3.13.15 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.14.0 (including) 3.14.7 (excluding)
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha8:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:beta1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:beta2:*:*:*:*:*:*