[CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
July 9, 2026
5:08 p.m.
There is a HIGH severity vulnerability affecting CPython.
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
Please see the linked CVE ID for the latest information on affected versions:
41
Age (days ago)
41
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson