CVE-2025-12084: Python
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.
Affected products
- Python Python: before 3.13.11 (fixed in 3.13.11); from 3.14.0, before 3.14.2 (fixed in 3.14.2); version 3.15.0 only
Published 2025-12-03. Last modified 2026-06-17.