CVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Other sources
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.12.14-1 - Upgrade
Upgrade
debian/python3.13to a version that resolves this vulnerability.Fixed in 3.13.15-1 - Upgrade
Upgrade
debian/python3.14to a version that resolves this vulnerability.Fixed in 3.14.7-3Fixed in 3.14.7-4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15308?
CVE-2026-15308 has a high severity rating of 8.7.
How do I fix CVE-2026-15308?
To fix CVE-2026-15308, update to the latest version of the Python html.parser module that addresses this vulnerability.
What type of attack does CVE-2026-15308 enable?
CVE-2026-15308 enables a CPU exhaustion denial-of-service (DoS) attack through repeated unterminated markup declarations.
Which software is affected by CVE-2026-15308?
CVE-2026-15308 affects the Python html.parser.HTMLParser module.
When was CVE-2026-15308 published?
CVE-2026-15308 was published on July 9, 2026.