Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.6%
probabilidad de explotación
0.6%top 57% de las CVE
explotación observada
noninguna fuente lo reporta
The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
Python Software Foundation · CPythonReferencias
https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969cedhttps://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bdhttps://github.com/python/cpython/issues/153030https://github.com/python/cpython/pull/153031https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/http://www.openwall.com/lists/oss-security/2026/07/09/4