CVE-2025-6069
published 2025-06-17CVE-2025-6069: The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified…
PriorityP418medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.47%
37.9th percentile
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jython | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | pypy3 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python2.7 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.11 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.13 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.9 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| msrc | azl3_python3_3.12.9-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-14_on_cbl_mariner_2.0 | — | — |
| python_software_foundation | cpython | < 3.10.19 | 3.10.19 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.14 | 3.11.14 |
| python_software_foundation | cpython | >= 3.12.0 < 3.12.12 | 3.12.12 |
| python_software_foundation | cpython | >= 3.13.0 < 3.13.6 | 3.13.6 |
| python_software_foundation | cpython | >= 3.14.0a1 < 3.14.0b3 | 3.14.0b3 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python 2.7 vulnerability
vendor_ubuntu·2025-08-29·CVSS 4.3
CVE-2025-8194 [MEDIUM] Python 2.7 vulnerability
Title: Python 2.7 vulnerability
Summary: Several security issues were fixed in Python.
USN-7710-1 fixed vulnerabilities in Python. This update provides the
corresponding fix for CVE-2025-8194 for Python 2.7.
Original advisory details:
It was discovered that Python inefficiently parsed maliciously crafted
HTML input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-6069)
It was discovered that Python incorrectly parsed maliciously crafted Tar
archives. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-8194)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-08-21·CVSS 4.3
CVE-2025-6069 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python inefficiently parsed maliciously crafted HTML
input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-6069)
It was discovered that Python incorrectly parsed maliciously crafted Tar
archives. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-8194)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cpython: Python HTMLParser quadratic complexity
vendor_redhat·2025-06-17·CVSS 4.3
CVE-2025-6069 [MEDIUM] CWE-1333 cpython: Python HTMLParser quadratic complexity
cpython: Python HTMLParser quadratic complexity
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
A denial-of-service (DoS) vulnerability has been discovered in Python's html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and de
Microsoft
HTMLParser quadratic complexity when processing malformed inputs
vendor_msrc·2025-06-10·CVSS 4.3
CVE-2025-6069 [MEDIUM] CWE-1333 HTMLParser quadratic complexity when processing malformed inputs
HTMLParser quadratic complexity when processing malformed inputs
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://
Debian
CVE-2025-6069: jython - The html.parser.HTMLParser class had worse-case quadratic complexity when proces...
vendor_debian·2025·CVSS 4.3
CVE-2025-6069 [MEDIUM] CVE-2025-6069: jython - The html.parser.HTMLParser class had worse-case quadratic complexity when proces...
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
python2.7 vulnerability
osv·2025-08-29·CVSS 4.3
CVE-2025-8194 [MEDIUM] python2.7 vulnerability
python2.7 vulnerability
USN-7710-1 fixed vulnerabilities in Python. This update provides the
corresponding fix for CVE-2025-8194 for Python 2.7.
Original advisory details:
It was discovered that Python inefficiently parsed maliciously crafted
HTML input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-6069)
It was discovered that Python incorrectly parsed maliciously crafted Tar
archives. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-8194)
OSV
python3.13, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
osv·2025-08-21·CVSS 4.3
CVE-2025-6069 [MEDIUM] python3.13, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
python3.13, python3.12, python3.11, python3.10, python3.9, python3.8, python3.7, python3.6, python3.5, python3.4 vulnerabilities
It was discovered that Python inefficiently parsed maliciously crafted HTML
input. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-6069)
It was discovered that Python incorrectly parsed maliciously crafted Tar
archives. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-8194)
OSV
CVE-2025-6069: The html
osv·2025-06-17·CVSS 4.3
CVE-2025-6069 [MEDIUM] CVE-2025-6069: The html
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
GHSA
GHSA-j5cc-6rx8-ff96: The html
ghsa_unreviewed·2025-06-17
CVE-2025-6069 [MEDIUM] CWE-1333 GHSA-j5cc-6rx8-ff96: The html
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-6069 python3.6: Python HTMLParser quadratic complexity [fedora-42]
bugzilla·2025-06-17·CVSS 4.3
CVE-2025-6069 [MEDIUM] CVE-2025-6069 python3.6: Python HTMLParser quadratic complexity [fedora-42]
CVE-2025-6069 python3.6: Python HTMLParser quadratic complexity [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2373234
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
We (Python-maint team) have decided not to proactively fix CVEs that are not present or requested to be fixed in RHEL for EOL Python interpreters that are in Fedora only for testing purposes.
---
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-
Bugzilla
CVE-2025-6069 cpython: Python HTMLParser quadratic complexity
bugzilla·2025-06-17·CVSS 4.3
CVE-2025-6069 [MEDIUM] CVE-2025-6069 cpython: Python HTMLParser quadratic complexity
CVE-2025-6069 cpython: Python HTMLParser quadratic complexity
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:23530 https://access.redhat.com/errata/RHSA-2025:23530
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:23342 https://access.redhat.com/errata/RHSA-2025:23342
https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4bhttps://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fchttps://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15https://github.com/python/cpython/issues/135462https://github.com/python/cpython/pull/135464https://mail.python.org/archives/list/[email protected]/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/
2025-06-17
Published