{
  "threat_severity" : "Important",
  "public_date" : "2026-07-09T17:10:57Z",
  "bugzilla" : {
    "description" : "python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations",
    "id" : "2498608",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2498608"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-835",
  "details" : [ "The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data.", "A flaw was found in Python. Its incremental HTML parser can be exploited by a remote attacker. By sending specially crafted, uncontrolled data with repeated, incomplete markup declarations, the attacker can cause the system to consume excessive central processing unit (CPU) resources. This leads to a denial of service, making the affected system unresponsive." ],
  "statement" : "This Important vulnerability in Python's `html.parser.HTMLParser` can lead to a denial of service. By supplying specially crafted, malformed HTML with repeated unterminated markup declarations, an attacker can cause excessive CPU consumption, rendering the system unresponsive. Red Hat products utilizing this parser to process untrusted HTML content are susceptible to resource exhaustion.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39183",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "python3.12-0:3.12.13-2.el10_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-16T00:00:00Z",
    "advisory" : "RHSA-2026:40856",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "python3.14-0:3.14.5-1.el10_2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39320",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "python3-0:3.6.8-77.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:39893",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "python3.12-0:3.12.13-3.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39320",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "python3-0:3.6.8-77.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:39771",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "python3.12-0:3.12.13-3.el9_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:39798",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "python3.9-0:3.9.25-7.el9_8.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:41949",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "python3.14-0:3.14.5-1.el9_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-15T00:00:00Z",
    "advisory" : "RHSA-2026:39798",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "python3.9-0:3.9.25-7.el9_8.2"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-10T00:00:00Z",
    "advisory" : "RHSA-2026:37533",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "python3-14-main-3.14.6-1.3.hum1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-10T00:00:00Z",
    "advisory" : "RHSA-2026:37535",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "python3-13-main-3.13.14-1.3.hum1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-10T00:00:00Z",
    "advisory" : "RHSA-2026:38017",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "python3-12-main-3.12.13-3.5.hum1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-10T00:00:00Z",
    "advisory" : "RHSA-2026:38018",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "python3-11-main-3.11.15-5.2.hum1",
    "impact" : "important"
  } ],
  "package_state" : [ {
    "product_name" : "Exploit Intelligence",
    "fix_state" : "Affected",
    "package_name" : "exploit-intelligence-tech-preview/vulnerability-analysis-rhel9",
    "cpe" : "cpe:/a:redhat:exploit_intelligence:0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "python",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "python",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "python3",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "python36:3.6/python36",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-aws-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-azure-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-azure-rocm-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-gaudi-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-gcp-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-rocm-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Affected",
    "package_name" : "container-native-virtualization/ocp-virt-validation-checkup-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Self-service automation portal 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform/bootc-automation-portal-rhel9",
    "cpe" : "cpe:/a:redhat:ansible_portal:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-15308\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15308\nhttps://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9\nhttps://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced\nhttps://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606\nhttps://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd\nhttps://github.com/python/cpython/issues/153030\nhttps://github.com/python/cpython/pull/153031\nhttps://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/" ],
  "name" : "CVE-2026-15308",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}