Bug 2418655 (CVE-2025-12084)

Summary: CVE-2025-12084 cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bbrownin, dfreiber, drow, gotiwari, jburrell, jgrulich, jhorak, ljawale, luizcosta, mvyas, nweather, rbobbitt, teagle, tpopela, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in cpython. This vulnerability allows impacted availability via a quadratic algorithm in `xml.dom.minidom` methods, such as `appendChild()`, when building excessively nested documents due to a dependency on `_clear_id_cache()`
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2422524, 2421608, 2421612, 2421614, 2421616, 2421620, 2421623, 2421625, 2421628, 2421630, 2421633, 2421636, 2421639, 2421642, 2422516, 2422517, 2422518, 2422519, 2422520, 2422521, 2422522    
Bug Blocks:    

Description OSIDB Bzimport 2025-12-03 19:01:30 UTC
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

Comment 2 errata-xmlrpc 2026-01-06 10:37:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:0123 https://access.redhat.com/errata/RHSA-2026:0123

Comment 4 errata-xmlrpc 2026-01-27 15:10:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1374 https://access.redhat.com/errata/RHSA-2026:1374

Comment 5 errata-xmlrpc 2026-01-27 17:17:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1408 https://access.redhat.com/errata/RHSA-2026:1408

Comment 6 errata-xmlrpc 2026-01-27 17:23:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1410 https://access.redhat.com/errata/RHSA-2026:1410

Comment 7 errata-xmlrpc 2026-01-28 10:33:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1478 https://access.redhat.com/errata/RHSA-2026:1478

Comment 8 errata-xmlrpc 2026-01-29 07:05:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:1537 https://access.redhat.com/errata/RHSA-2026:1537

Comment 9 errata-xmlrpc 2026-01-29 09:36:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:1558 https://access.redhat.com/errata/RHSA-2026:1558

Comment 11 errata-xmlrpc 2026-01-29 14:19:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:1582 https://access.redhat.com/errata/RHSA-2026:1582

Comment 12 errata-xmlrpc 2026-01-29 14:28:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:1583 https://access.redhat.com/errata/RHSA-2026:1583

Comment 13 errata-xmlrpc 2026-02-02 01:22:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2026:1620 https://access.redhat.com/errata/RHSA-2026:1620

Comment 14 errata-xmlrpc 2026-02-02 01:59:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1631 https://access.redhat.com/errata/RHSA-2026:1631

Comment 16 errata-xmlrpc 2026-02-03 15:30:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:1828 https://access.redhat.com/errata/RHSA-2026:1828

Comment 17 errata-xmlrpc 2026-02-04 15:00:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:1922 https://access.redhat.com/errata/RHSA-2026:1922

Comment 18 errata-xmlrpc 2026-02-04 19:33:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:1892 https://access.redhat.com/errata/RHSA-2026:1892

Comment 19 errata-xmlrpc 2026-02-04 19:44:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:1893 https://access.redhat.com/errata/RHSA-2026:1893

Comment 20 errata-xmlrpc 2026-02-05 11:54:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:2084 https://access.redhat.com/errata/RHSA-2026:2084

Comment 22 errata-xmlrpc 2026-02-09 02:05:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:2233 https://access.redhat.com/errata/RHSA-2026:2233

Comment 23 errata-xmlrpc 2026-02-09 08:11:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:2276 https://access.redhat.com/errata/RHSA-2026:2276

Comment 24 errata-xmlrpc 2026-02-09 08:18:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:2275 https://access.redhat.com/errata/RHSA-2026:2275

Comment 25 errata-xmlrpc 2026-02-09 12:07:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:2330 https://access.redhat.com/errata/RHSA-2026:2330

Comment 27 errata-xmlrpc 2026-02-10 08:07:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:2393 https://access.redhat.com/errata/RHSA-2026:2393

Comment 28 errata-xmlrpc 2026-02-10 08:07:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:2391 https://access.redhat.com/errata/RHSA-2026:2391

Comment 29 errata-xmlrpc 2026-02-10 08:13:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:2392 https://access.redhat.com/errata/RHSA-2026:2392

Comment 30 errata-xmlrpc 2026-02-16 11:03:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:2713 https://access.redhat.com/errata/RHSA-2026:2713