The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
高危 CVSS 7.5
摘要
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9 Patch
- https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14
- https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced Patch
- https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606 Patch
- https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd Patch
- https://github.com/python/cpython/issues/153030 Patch
- https://github.com/python/cpython/pull/153031 Issue Tracking
- https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/ Mailing List
- http://www.openwall.com/lists/oss-security/2026/07/09/4 Third Party Advisory
时间线
- nvd_ingest NVD