CVE-2025-6069: Python Software Foundation Cpython

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

Affected products

  • Python Software Foundation Cpython: before 3.9.24 (fixed in 3.9.24); from 3.10.0, before 3.10.19 (fixed in 3.10.19); from 3.11.0, before 3.11.14 (fixed in 3.11.14); from 3.12.0, before 3.12.12 (fixed in 3.12.12); from 3.13.0, before 3.13.6 (fixed in 3.13.6); from 3.14.0a1, before 3.14.0b3 (fixed in 3.14.0b3)

Published 2025-06-17. Last modified 2026-07-31.