CVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Published Jul 9, 2026
·Updated
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
Affected Software
18 affected components
Python html.parser.HTMLParser
Python Python<3.10.21
Python Python>=3.11.0<3.11.16
Python Python>=3.12.0<3.12.14
Python Python>=3.13.0<3.13.15
Python Python>=3.14.0<3.14.7
Python Python=3.15.0-alpha1
Python Python=3.15.0-alpha2
Python Python=3.15.0-alpha3
Python Python=3.15.0-alpha4
Python Python=3.15.0-alpha5
Python Python=3.15.0-alpha6
Python Python=3.15.0-alpha7
Python Python=3.15.0-alpha8
Python Python=3.15.0-beta1
Python Python=3.15.0-beta2
Python Python=3.15.0-beta3
IBM Observability with Instana (Agent)<=Build 1.0.303 to 1.0.323
Remediation
Patch Available
Patch Available
Event History
Jul 9, 2026
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Sep 2, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15308?
CVE-2026-15308 has a high severity rating of 8.7.
2
How do I fix CVE-2026-15308?
To fix CVE-2026-15308, update to the latest version of the Python html.parser module that addresses this vulnerability.
3
What type of attack does CVE-2026-15308 enable?
CVE-2026-15308 enables a CPU exhaustion denial-of-service (DoS) attack through repeated unterminated markup declarations.
4
Which software is affected by CVE-2026-15308?
CVE-2026-15308 affects the Python html.parser.HTMLParser module.
5
When was CVE-2026-15308 published?
CVE-2026-15308 was published on July 9, 2026.