CVE-2026-15308: Python
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
Affected products
- Python Python: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); version 3.15.0 only
Published 2026-07-09. Last modified 2026-08-20.