# CVE-2026-15308

## Summary

- **CVE ID:** CVE-2026-15308
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-400
- **Published:** Jul 9, 2026
- **Last Modified:** Aug 13, 2026

## Description

The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.

## Affected Products

- Python Software Foundation — CPython (0)
- Python Software Foundation — CPython (3.15.0a1)
- Python Software Foundation — CPython (3.14.0)
- Python Software Foundation — CPython (3.11.0)
- Python Software Foundation — CPython (3.12.0)
- Python Software Foundation — CPython (3.13.0)

## References

- [CNA](https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/)
- [CNA](https://github.com/python/cpython/pull/153031)
- [CNA](https://github.com/python/cpython/issues/153030)
- [CNA](https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9)
- [CNA](https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced)
- [CNA](https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606)
- [CNA](https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd)
- [CVE](http://www.openwall.com/lists/oss-security/2026/07/09/4)
- [CNA](https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14)
- [CNA](https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7)
- [CNA](https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.64%
- **EPSS Percentile:** 48.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._