Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.7epss 0.6%
probabilidade de exploração
0.6%top 54% das CVEs
exploração observada
nãonenhuma fonte reporta
The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Python Software Foundation · CPythonReferências
https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969cedhttps://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bdhttps://github.com/python/cpython/issues/153030https://github.com/python/cpython/pull/153031https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/http://www.openwall.com/lists/oss-security/2026/07/09/4