๐Ÿ” CVE Alert

CVE-2025-6069

MEDIUM 4.3

HTMLParser quadratic complexity when processing malformed inputs

CVSS Score
4.3
EPSS Score
0.9%
EPSS Percentile
75th

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

CWE CWE-1333
Vendor python software foundation
Product cpython
Published Jun 17, 2025
Last Updated Apr 21, 2026
Stay Ahead of the Next One

Get instant alerts for python software foundation cpython

Be the first to know when new medium vulnerabilities affecting python software foundation cpython are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

Python Software Foundation / CPython
0 < 3.10.19 3.11.0 < 3.11.14 3.12.0 < 3.12.12 3.13.0 < 3.13.6 3.14.0a1 < 3.14.0b3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/python/cpython/issues/135462 github.com: https://github.com/python/cpython/pull/135464 github.com: https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949 github.com: https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41 github.com: https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b mail.python.org: https://mail.python.org/archives/list/[email protected]/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/ github.com: https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49 github.com: https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5 github.com: https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc github.com: https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15

Credits

Serhiy Storchaka ๐Ÿ” Jake Howard sw0rd1ight