CVE-2026-15308
HighAdvisory
Published 9 Jul 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.006
- 49th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 869
- of 17,781 indexed, latest versions
- Container images
- 899
- deployed by those charts
- Fix available
- 17 of 18
- affected packages
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Carried by container images the latest versions of 869 of 17,781 indexed charts deploy, on 899 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| python-3.14apk | 3.14.2-r2, 3.14.4-r2, 3.14.6-r0 | 3.14.6-r4 | 6 |
| pythonbitnami | 3.11.11-0, 3.12.8-0, 3.13.5-1 | 3.10.21 | 3 |
| python-3.13apk | 3.13.7-r0, 3.13.10-r0, 3.13.12-r2 | 3.13.14-r3 | 3 |
| python-3.12apk | 3.12.0-r1, 3.12.9-r1 | 3.12.14-r2 | 2 |
| python3.11deb | 3.11.0~rc1-1~22.04, 3.11.0~rc1-1~22.04.1, 3.11.2-6, 3.11.2-6+deb12u2+6 more | 3.11.0~rc1-1~22.04.1+esm2 | 181 |
| python3rpm | 3.6.8-15.1.el8, 3.6.8-23.el8, 3.6.8-24.el8_2, 3.6.8-24.el8_2.2+28 more | 0:3.6.8-77.el8_10, 0:3.6.8-77.el8_10.rocky.0, 3.12.14-1 | 136 |
| python3.8deb | 3.8.5-1~20.04, 3.8.5-1~20.04.2, 3.8.5-1~20.04.3, 3.8.10-0ubuntu1~20.04+11 more | 3.8.10-0ubuntu1~20.04.18+esm7 | 100 |
| python3.12deb | 3.12.3-1, 3.12.3-1ubuntu0.2, 3.12.3-1ubuntu0.3, 3.12.3-1ubuntu0.4+10 more | 3.12.3-1ubuntu0.17 | 87 |
| python3.10deb | 3.10.4-3, 3.10.4-3ubuntu0.1, 3.10.6-1~22.04, 3.10.6-1~22.04.1+16 more | 3.10.12-1~22.04.18 | 80 |
| python3apk | 3.11.12-r1, 3.12.8-r1, 3.12.9-r0, 3.12.10-r0+7 more | 3.12.14-r0, 3.14.7-r0 | 75 |
| python3.13deb | 3.13.5-2, 3.13.5-2+deb13u2, 3.13.5-2+deb13u4 | no fix listed | 73 |
| python3.9rpm | 3.9.16-1.el9, 3.9.16-1.el9_2.1, 3.9.16-1.el9_2.2, 3.9.18-1.el9_3.1+15 more | 0:3.9.25-7.el9_8.2 | 55 |
| python3.6deb | 3.6.6-1~18.04, 3.6.7-1~18.04, 3.6.9-1~18.04, 3.6.9-1~18.04ubuntu1+7 more | 3.6.9-1~18.04ubuntu1.13+esm10 | 44 |
| python2.7deb | 2.7.6-8, 2.7.6-8ubuntu0.4, 2.7.12-1ubuntu0~16.04.2, 2.7.12-1ubuntu0~16.04.3+9 more | 2.7.6-8ubuntu0.6+esm30, 2.7.12-1ubuntu0~16.04.18+esm22, 2.7.17-1~18.04ubuntu1.13+esm15, 2.7.18-13ubuntu1.5+esm9 | 43 |
| python3.5deb | 3.5.2-2ubuntu0~16.04.1, 3.5.2-2ubuntu0~16.04.4, 3.5.2-2ubuntu0~16.04.5, 3.5.2-2ubuntu0~16.04.9 | 3.5.2-2ubuntu0~16.04.13+esm25 | 25 |
| python3.14deb | 3.14.4-1, 3.14.4-1ubuntu0.1 | 3.14.4-1ubuntu0.2 | 8 |
| python3.4deb | 3.4.0-2ubuntu1, 3.4.3-1ubuntu1~14.04.5, 3.4.3-1ubuntu1~14.04.6, 3.4.3-1ubuntu1~14.04.7 | 3.4.3-1ubuntu1~14.04.7+esm21 | 7 |
| python3.12rpm | 3.12.5-2.el9_5.2 | 0:3.12.13-3.el9_8.1 | 1 |
- OSV records
- ALPINE-CVE-2026-15308BIT-python-2026-15308CGA-2v5h-4pjx-m2vpCGA-7fq5-cfqp-92mfCGA-8wxj-3m53-wmwrDEBIAN-CVE-2026-15308RHSA-2026:39320RHSA-2026:39771RHSA-2026:39798RLSA-2026:39320RLSA-2026:39798UBUNTU-CVE-2026-15308AZL-92271
- Also known as
- BIT-libpython-2026-15308, BIT-python-min-2026-15308, CGA-qq9v-hh37-fr79, CGA-vh53-c7h5-695j, CGA-xm2p-hf9g-qw3m, PSF-2026-33, RHSA-2026:50064, RHSA-2026:50065, RHSA-2026:50816, USN-8744-1
Charts affected
869 by stars
Container images carrying it
899 by charts deploying them
A fixed version is listed for 17 of the 18 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| moreillon/ | e1c9bfab5c16 | python3.11 | no fix listed | 2 |
| nacos/ | 1c191c30c8cd | python3.14 | 3.14.4-1ubuntu0.2 | 2 |
| nutanix/ | 9c373718e1b1 | python3.13 | no fix listed | 2 |
| obolnetwork/ | 278c7e2897b6 | python3.13 | no fix listed | 2 |
| omecproject/ | cfdb566dd949 | python2.7 python3.5 | 2.7.12-1ubuntu0~16.04.18+esm22 3.5.2-2ubuntu0~16.04.13+esm25 | 2 |
| opendatacube/ | 668cbb41473c | python3.12 | 3.12.3-1ubuntu0.17 | 2 |
| qichenxu4pd/ | f3a8502bc21b | python3.11 | no fix listed | 2 |
| redis/ | 1c5f43fddcdd | python3.10 | 3.10.12-1~22.04.18 | 2 |
| redis/ | 72035434f455 | python3.10 | 3.10.12-1~22.04.18 | 2 |
| redis/ | e44b2b49d059 | python3.10 | 3.10.12-1~22.04.18 | 2 |
| smartedge/ | 4cd63c22ce36 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 2 |
| stakater/ | 954d2be66e95 | python3 | 0:3.6.8-77.el8_10 | 2 |
| streamnative/ | 0e6d7aa3ef32 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 2 |
| svtechnmaa/ | b2987abe57d3 | python3.10 | 3.10.12-1~22.04.18 | 2 |
| tzahi12345/ | 2f943d584711 | python3.10 | 3.10.12-1~22.04.18 | 2 |
| uffizzi/ | 0344805f267b | python3.11 | no fix listed | 2 |
| vdiogov/ | 6945f84f0058 | python3.11 | no fix listed | 2 |
| wurstmeister/ | 7a7fd44a7210 | python2.7 python3.4 | 2.7.6-8ubuntu0.6+esm30 3.4.3-1ubuntu1~14.04.7+esm21 | 2 |
| ghcr.io/ | 82d0b161161d | python3.12 | 3.12.3-1ubuntu0.17 | 2 |
| ghcr.io/ | 5be52524664c | python2.7 python3.10 | 2.7.18-13ubuntu1.5+esm9 3.10.12-1~22.04.18 | 2 |
| ghcr.io/ | 103fbcec2314 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 2 |
| ghcr.io/ | cd264d33efd4 | python3.11 | no fix listed | 2 |
| ghcr.io/ | 4ee0764310e7 | python2.7 | 2.7.17-1~18.04ubuntu1.13+esm15 | 2 |
| ghcr.io/ | 33e60bfb40f2 | python3 | 3.12.14-r0 | 2 |
| ghcr.io/ | 4457b79b24cd | python3.11 | no fix listed | 2 |
| ghcr.io/ | 647a3c938d31 | python-3.14 | 3.14.6-r4 | 2 |
| mcr.microsoft.com/ | 902628a8be89 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 2 |
| public.ecr.aws/ | d20bd62f0182 | python3.9 | 0:3.9.25-7.el9_8.2 | 2 |
| quay.io/ | cb009167015c | python3 | 3.14.7-r0 | 2 |
| quay.io/ | 8745af1f9bbb | python3 | 3.12.14-r0 | 2 |
| quay.io/ | 054ef67eb7da | python3 | 0:3.6.8-77.el8_10 | 2 |
| quay.io/ | 68f9f38c8f30 | python3 | 0:3.6.8-77.el8_10 | 2 |
| quay.io/ | 464a3af4dfe0 | python3 | 0:3.6.8-77.el8_10 | 2 |
| quay.io/ | bb5e052770e5 | python3 | 0:3.6.8-77.el8_10 | 2 |
| quay.io/ | 5fb28e9f30d0 | python3.9 | 0:3.9.25-7.el9_8.2 | 2 |
| quay.io/ | 02f6f143fc6d | python3 | 0:3.6.8-77.el8_10 | 2 |
| quay.io/ | ac434a48ac2b | python3.9 | 0:3.9.25-7.el9_8.2 | 2 |
| registry.gitlab.com/ | b1198ea741d1 | python3 | 3.12.14-r0 | 2 |
| registry.k8s.io/ | dc7746bb081e | python3.11 | no fix listed | 2 |
| a10networks/ | 8dc58d434d71 | python3.6 | 3.6.9-1~18.04ubuntu1.13+esm10 | 1 |
| aapjeisbaas/ | 6b261abc7fb0 | python3.13 | no fix listed | 1 |
| aboogie/ | 9c41a4483ac8 | python3.11 | no fix listed | 1 |
| adwerx/ | 840d2b078682 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| aerospike/ | f35739b97a46 | python3 | 3.14.7-r0 | 1 |
| agentarea/ | d3c209a5d531 | python3.11 | no fix listed | 1 |
| airsonicadvanced/ | f7cbafac2806 | python3.8 | 3.8.10-0ubuntu1~20.04.18+esm7 | 1 |
| akeyless/ | 759e4289fae8 | python3.12 | 3.12.3-1ubuntu0.17 | 1 |
| akeyless/ | 4ba8900a0061 | python3 | 0:3.6.8-77.el8_10 | 1 |
| akeyless/ | 3d2e7dce5eb9 | python3.12 | 3.12.3-1ubuntu0.17 | 1 |
| aktosecurity/ | fcf8be10bead | python3 | 3.12.14-r0 | 1 |