CVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Published Jul 9, 2026
·Updated
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
Affected Software
2 affected components
Python html.parser.HTMLParser
Python Python<3.15.0
Remediation
Patch Available
Patch Available
Event History
Jul 9, 2026
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15308?
CVE-2026-15308 has a high severity rating of 8.7.
2
How do I fix CVE-2026-15308?
To fix CVE-2026-15308, update to the latest version of the Python html.parser module that addresses this vulnerability.
3
What type of attack does CVE-2026-15308 enable?
CVE-2026-15308 enables a CPU exhaustion denial-of-service (DoS) attack through repeated unterminated markup declarations.
4
Which software is affected by CVE-2026-15308?
CVE-2026-15308 affects the Python html.parser.HTMLParser module.
5
When was CVE-2026-15308 published?
CVE-2026-15308 was published on July 9, 2026.