Bug 2373241 - CVE-2025-6069 python3.13: Python HTMLParser quadratic complexity [fedora-41]
Summary: CVE-2025-6069 python3.13: Python HTMLParser quadratic complexity [fedora-41]
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: python3.13
Version: 41
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Python Maintainers
QA Contact:
URL:
Whiteboard: {"flaws": ["99bc79c2-d25b-4921-a562-5...
Depends On:
Blocks: CVE-2025-6069
TreeView+ depends on / blocked
 
Reported: 2025-06-17 16:18 UTC by Jon Moroney
Modified: 2025-10-22 12:10 UTC (History)
5 users (show)

Fixed In Version: python3.13-3.13.7-1.fc41
Clone Of:
Environment:
Last Closed: 2025-10-22 12:10:42 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2025-06-17 16:18:51 UTC
More information about this security flaw is available in the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=2373234

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Lumír Balhar 2025-06-28 09:47:33 UTC
The fix has been merged upstream but not yet released: https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949

Comment 2 Miro Hrončok 2025-07-09 12:15:38 UTC
Waiting for the next Python 3.13 release.


Note You need to log in before you can comment on or make changes to this bug.