Bug 2498693 - CVE-2026-15308 python3.9: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations [fedora-all]
Summary: CVE-2026-15308 python3.9: Python: CPU Denial of Service in HTML parser via re...
Keywords:
Status: POST
Alias: None
Product: Fedora
Classification: Fedora
Component: python3.9
Version: 45
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Miro Hrončok
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["e4e01e88-5029-4403-9e37-e...
Depends On:
Blocks: CVE-2026-15308
TreeView+ depends on / blocked
 
Reported: 2026-07-09 20:10 UTC by Jon Moroney
Modified: 2026-09-23 13:02 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-07 05:55:28 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Fedora Package Sources python3.9 pull-request 252 0 None None None 2026-09-23 13:02:13 UTC

Description Jon Moroney 2026-07-09 20:10:20 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.

Comment 1 Aoife Moloney 2026-08-17 15:16:47 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.

Comment 2 Miro Hrončok 2026-09-23 12:08:06 UTC
c9s fix is https://gitlab.com/redhat/centos-stream/rpms/python3.9/-/commit/0ad244b12d3adcc81d14e6c9dc974351dc77d2a4 -- we need to forwardport it


Note You need to log in before you can comment on or make changes to this bug.