Skip to content

CVE-2026-15308: CPython HTMLParser.feed() Unterminated Markup CPU Exhaustion DoS

HERMES

HERMES THREAT SCORE & APPLICATION RUNTIME ATTACK SURFACE

Target: CPython (Lib/html/parser.py - HTMLParser)
Confidence: 94%
84 / 100
HIGH

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 18 / 20
Threat Activity 16 / 20
Weaponization 17 / 20
Exposure 18 / 20
Prevalence 19 / 20
Impact 18 / 20
Exploit Maturity 17 / 20
Attack Chain Potential 19 / 20
โš–๏ธ Divergence & Operational Rationale

CVSS v3.1 rates CVE-2026-15308 at 7.5 (HIGH, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The Hermes Threat Score evaluates operational impact at 84 (HIGH) reflecting broad ecosystem exposure across data pipelines, MLOps, and developer environments.

๐Ÿ•ธ๏ธ Connected Knowledge Graph & Provenance

CVE-2026-15308: CPython HTMLParser.feed() Unterminated Markup CPU Exhaustion DoSVULNERABILITY

Connected Nodes: 2
Active Relationships (Outgoing)
→ affectsPRODUCTCPython Interpreter & Standard Library
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

๐Ÿ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier.”

Supporting Verified Evidence:
→ usesATTACK TECHNIQUET1059: Command and Scripting Interpreter
90% VERY_HIGH

Adversaries abuse command and script interpreters (Bash, Python, PowerShell) to execute arbitrary commands.

๐Ÿ” Why is this related? (Evidence & Provenance)

“Attack execution telemetry aligns with MITRE ATT&CK technique T1059.”

Supporting Verified Evidence:

The component CPython (Lib/html/parser.py - HTMLParser) provides fundamental runtime services and data parsing across Python microservices, analytics pipelines, and AI platforms.

ParameterTechnical SpecificationThreat Intelligence Context
CVE IdentifierCVE-2026-15308Official Upstream Security Release
Affected Productpython:cpythonPython Ecosystem Component
Vulnerable ComponentCPython (Lib/html/parser.py - HTMLParser)Standard Library / Package Utility
Weakness ClassCWE-400: Uncontrolled Resource ConsumptionExecution / Resource Safety Flaw
CVSS v3.1 Score7.5 (HIGH / Hermes Score 84)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed Version3.13.15Official upstream patch release
MITRE ATT&CKT1499 - Endpoint Denial of Service, T1059.006 - PythonExecution / Denial of Service
Forensic Cross-ReferenceLinux Process and CPU Starvation Forensic AnalysisMemory analysis and process diagnostics

Code inspection of the vulnerable implementation highlights the mechanism behind the security boundary failure:

# Flaw in Lib/html/parser.py (HTMLParser.goahead)
def goahead(self, end):
rawdata = self.rawdata
i = 0
n = len(rawdata)
while i < n:
if rawdata.startswith("<!", i):
# VULNERABILITY: If declaration is unterminated,
# parse_html_declaration fails and loop breaks without advancing i!
# Next feed() call re-scans the entire buffer from index 0!
k = self.parse_html_declaration(i)
if k < 0:
break # Re-scans all previous bytes on every feed() chunk!

When unvetted user input reaches this routine, the application encounters an unhandled edge case or unbounded processing loop, destabilizing the execution environment or enabling control-flow manipulation.


  1. Initial Vector & Preconditions: An attacker points a web scraper, indexing bot, or LLM agent to a web page containing thousands of streaming chunks of <!DOCTYPE [ ... without closing brackets.
  2. Triggering Primitive: The attacker injects crafted payload data targeting CPython (Lib/html/parser.py - HTMLParser).
  3. Control Bypass / Resource Saturation: Flaw in Lib/html/parser.py (HTMLParser.goahead).
  4. Impact Realization: The scraperโ€™s ingestion thread hits 100% CPU on a single core and stops accepting new scraping tasks..

Security operations centers and incident response teams can identify exploitation activity through process telemetry, memory dumps, and operating system audit trails.

Process Telemetry & Logs

Inspect application logs and process crash diagnostics matching: kernel: Process [pid] (python3) excessive CPU runtime in HTMLParser.goahead. Monitor for abnormal CPU spikes or unexpected out-of-memory terminations.

sigma_cve_2026_15308.yaml
title: Python Web Scraper CPU Starvation via HTMLParser Unterminated Feed
id: cve-2026-15308
status: experimental
description: Detects anomalies and resource abuse associated with CVE-2026-15308.
logsource:
category: process_creation
product: linux
detection:
selection:
- 'kernel:'
- 'cpython'
condition: selection
fields:
- CommandLine
- User
level: high

Immediate remediation involves upgrading to patched library versions and enforcing input sanitization best practices:

  1. Package Upgrade: Update python:cpython to version 3.13.15 or higher using pip install --upgrade or distribution security repositories.
  2. Defensive Programming: Enforce strict size quotas, input schema validation, and disable unsafe deserialization primitives (replace pickle with safetensors or JSON).
  3. Forensic Guidance: For complete forensic telemetry workflows, consult our guide on Linux Process and CPU Starvation Forensic Analysis.