Description
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Scores
CVSS v3
4.3
EPSS
0.0086
EPSS Percentile
75.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Products (7)
Python Software Foundation/CPython
< 3.10.19
Python Software Foundation/CPython
< 3.9.24
Python Software Foundation/CPython
3.10.0 - 3.10.19
Python Software Foundation/CPython
3.11.0 - 3.11.14
Python Software Foundation/CPython
3.12.0 - 3.12.12
Python Software Foundation/CPython
3.13.0 - 3.13.6
Python Software Foundation/CPython
3.14.0a1 - 3.14.0b3
Published
Jun 17, 2025
Tracked Since
Feb 18, 2026