CVE-2026-15308Disclosure(python / python)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • python

Threat summary

  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-07-09); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
python

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-07-09: 3Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-13: 1Mentions · 2026-08-07: 1Technical Details · 2026-07-09: 2Technical Details · 2026-07-10: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-07: 107-0907-1007-1107-1308-07
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-093
Disclosure2General1
2026-07-101
Disclosure1
2026-07-111
Disclosure1
2026-07-131
General1
2026-08-071
Disclosure1
Full discourse7 posts
  • sushi com abacate@sushicomabacate
    General

    Microsoft acabou de me dar um susto Recebi esse email e pensei: que diabo de CVE é esse CVSS 10 no Python? CVE-2026-15308 🤔 #bolhasec https://t.co/Nfg9aOUfPS

    Post summary

    The tweet simply references a CVE with a CVSS 10 score but offers no technical details, tactics, or evidence of exploitation, making it a general mention.

    1102203.3K
    10.3K followersView on X
  • Mehmet INCE@mdisec
    Disclosure

    I mean latest python vulnerability CVE-2026-15308 is sounds great but `The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.` Why do we have this CVSS 10 score really ?

    Post summary

    The text references CVE‑2026‑15308, detailing a denial‑of‑service flaw in Python’s HTML parser, while questioning the CVSS score but providing no further technical or operational context.

    0001564.5K
    34.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-15308: CPython: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations https://www.openwall.com/lists/oss-security/2026/07/09/4

    Post summary

    The text announces a new CPython flaw (CVE-2026-15308) that causes CPU exhaustion through repeated unterminated markup in the Incremental HTMLParser, with no mention of exploits or patches.

    01021777
    4.7K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-15308: Python HTML Parser CPU Denial-of-Service Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04skddL0

    Post summary

    The post identifies CVE‑2026‑15308 as a CPU‑based DoS flaw in Python’s HTML parser and provides business‑impact guidance, but does not present a PoC, exploit code, or active exploitation evidence.

    0000036
    32 followersView on X
  • DailyCVE@dailycve
    General

    🔴 CPython, CPU Denial-of-Service, #CVE-2026-15308 (High) -DC-Jul2026-885 https://dailycve.com/cpython-cpu-denial-of-service-cve-2026-15308-high-dc-jul2026-885/

    Post summary

    The text announces a high‑severity CPython CPU denial‑of‑service vulnerability (CVE‑2026‑15308) and provides only basic details and a link, with no PoC, exploit, or mitigation information.

    0000057
    218 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - CPython HTMLParser CPU Denial of Service via Unterminated Markup Declarations (CVE-2026-15308) CVE-2026-15308 is a CPU denial-of-service issue in CPython’s incremental HTML parser, specifically the standard library component html.parser.HTMLParser when processing untrusted HTML input. The root cause is improper input handling that allows pathological parsing behavior (algorithmic complexity/resource exhaustion) when markup declarations are left unterminated repeatedly. An attacker can exploit this by sending crafted HTML containing repeated unterminated markup declarations to any service or pipeline that parses attacker-controlled content with HTMLParser, requiring no special privileges beyond the ability to supply input. Successful exploitation can peg CPU cores and degrade or fully take down affected applications, causing denial of service and cascading availability impacts. 👉 Affected: CPython (html.parser.HTMLParser) | Upgrade to No fix yet — treat as suspicious

    Post summary

    CVE‑2026‑15308 is a newly disclosed CPU denial‑of‑service vulnerability in CPython’s HTMLParser caused by repeated unterminated markup declarations, with no patch available yet.

    0000096
    246 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - CPython HTMLParser CPU Denial of Service via Unterminated Markup Declarations (CVE-2026-15308) CVE-2026-15308 is a CPU denial-of-service issue in CPython’s incremental HTML parser, specifically the standard library component html.parser.HTMLParser when processing untrusted HTML input. The root cause is improper input handling that allows pathological parsing behavior (algorithmic complexity/resource exhaustion) when markup declarations are left unterminated repeatedly. An attacker can exploit this by sending crafted HTML containing repeated unterminated markup declarations to any service or pipeline that parses attacker-controlled content with HTMLParser, requiring no special privileges beyond the ability to supply input. Successful exploitation can peg CPU cores and degrade or fully take down affected applications, causing denial of service and cascading availability impacts. 👉 Affected: CPython (html.parser.HTMLParser) | Upgrade to No fix yet — treat as suspicious

    Post summary

    A newly disclosed CVE-2026-15308 details a CPU denial‑of‑service in CPython's HTMLParser caused by unterminated markup declarations; no patch is available yet.

    00000105
    246 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpython---
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--

Explore more