CVE Tracker

CVE-2026-15308 @ mufasa

Status
accepted_risk
Priority
7.0
Match score
4.0
Risk
DoS Remote
CVSS
7.5 HIGH
Reason
cpe: python; pkgs: python, python-augeas, python-babel, python-backports, python-backports-ssl_match_hostname, python-chardet; version: in-range: python-2.7.5-94.0.5.el7_9.tuxcare.els1, python-augeas-0.5.0-2.el7, python-babel-0.9.6-8.el7, python-backports-1.0-8.el7, python-backports-ssl_match_hostname-3.5.0.1-1.el7, python-chardet-2.2.1-3.el7; risk:dos
Created
2026-08-02T19:35:36Z
Updated
2026-08-22T10:15:33Z
Closed
2026-08-04T19:00:34Z

Package interrogation (copy)

Run on the host — click to copy a command. RPM

PackageCommands
python-2.7.5-94.0.5.el7_9.tuxcare.els1
python-augeas-0.5.0-2.el7
python-babel-0.9.6-8.el7
python-backports-1.0-8.el7
python-backports-ssl_match_hostname-3.5.0.1-1.el7
python-chardet-2.2.1-3.el7

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: python · python-augeas · python-babel · python-backports · python-backports-ssl_match_hostname · python-chardet

SystemMatchesTicket for CVE-2026-15308
Archive libpython-stdlib 2.7.16-1; libpython2-stdlib 2.7.16-1; libpython2.7 2.7.16-2+deb10u4; libpython2.7-minimal 2.7.16-2+deb10u4; libpython2.7-stdlib 2.7.16-2+deb10u4; libpython3-stdlib 3.7.3-1; libpython3.5-minimal 3.5.3-1+deb9u5; libpython3.7-minimal 3.7.3-2+deb10u7 (+28 more) accepted_risk open
Library dh-python 2.20170125; libpython-stdlib 2.7.13-2; libpython2.7 2.7.13-2+deb9u6; libpython2.7-minimal 2.7.13-2+deb9u6; libpython2.7-stdlib 2.7.13-2+deb9u6; libpython3-stdlib 3.5.3-1; libpython3.5 3.5.3-1+deb9u5; libpython3.5-minimal 3.5.3-1+deb9u5 (+21 more) accepted_risk open
Matrix libpython2.7-minimal 2.7.18-8+deb11u1; libpython2.7-stdlib 2.7.18-8+deb11u1; libpython3-stdlib 3.11.2-1+b1; libpython3.11 3.11.2-6+deb12u8; libpython3.11-minimal 3.11.2-6+deb12u8; libpython3.11-stdlib 3.11.2-6+deb12u8; python 2.7.16-1; python-apt-common 2.6.0 (+34 more) accepted_risk open
Saiph libpython-stdlib 2.7.16-1; libpython2-stdlib 2.7.16-1; libpython2.7 2.7.16-2+deb10u4; libpython2.7-minimal 2.7.16-2+deb10u4; libpython2.7-stdlib 2.7.16-2+deb10u4; libpython3-stdlib 3.7.3-1; libpython3.5-minimal 3.5.3-1+deb9u1; libpython3.7 3.7.3-2+deb10u7 (+23 more) accepted_risk open
morris alt-python-internal 3.11.13; alt-python-internal-libs 3.11.13; alt-python-internal-pip-wheel 21.3.1; alt-python-internal-setuptools-wheel 65.6.3; alt-python-virtualenv 20.13.0; alt-python27 2.7.18; alt-python27-alembic 0.8.3; alt-python27-argparse 1.2.1 (+341 more) accepted_risk open
mufasa abrt-addon-python 2.1.11; abrt-python 2.1.11; alt-python-internal 3.11.13; alt-python-internal-libs 3.11.13; alt-python-internal-pip-wheel 21.3.1; alt-python-internal-setuptools-wheel 65.6.3; alt-python-virtualenv 20.13.0; alt-python27 2.7.18 (+198 more) accepted_risk open
Bullseye libpython3-stdlib 3.9.2-3; libpython3.9 3.9.2-1+deb11u7; libpython3.9-minimal 3.9.2-1+deb11u7; libpython3.9-stdlib 3.9.2-1+deb11u7; python-apt-common 2.2.1.1; python3 3.9.2-3; python3-apt 2.2.1.1; python3-certifi 2020.6.20-1 (+30 more) none
Helios libpython3-stdlib 3.9.2-3; libpython3.9 3.9.2-1+deb11u7; libpython3.9-minimal 3.9.2-1+deb11u7; libpython3.9-stdlib 3.9.2-1+deb11u7; python-apt-common 2.2.1.1; python-is-python3 3.9.2-1; python3 3.9.2-3; python3-apt 2.2.1.1 (+29 more) none
Janus libpython2.7 2.7.16-2+deb10u4; libpython2.7-minimal 2.7.16-2+deb10u4; libpython2.7-stdlib 2.7.16-2+deb10u4; libpython3-stdlib 3.7.3-1; libpython3.7-minimal 3.7.3-2+deb10u7; libpython3.7-stdlib 3.7.3-2+deb10u7; python3 3.7.3-1; python3-minimal 3.7.3-1 (+2 more) none
Silk alt-python-internal 3.11.14-1; alt-python-internal-libs 3.11.14-1; alt-python-internal-pip-wheel 21.3.1-1; alt-python-internal-setuptools-wheel 65.6.3-1; alt-python311 3.11.9-1; alt-python311-libs 3.11.9-1; alt-python311-pip-wheel 21.3.1-1; alt-python311-setuptools-wheel 65.6.3-1 (+50 more) none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-68770 9.8 morris, mufasa does_not_affect python
CVE-2026-3644 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk, does_not_affect python-chardet
CVE-2026-4224 7.5 Archive, Library, Saiph, morris, mufasa accepted_risk, does_not_affect python-chardet
CVE-2026-7210 7.5 Archive, Library, Matrix, Saiph, morris accepted_risk, not_applicable python-chardet → CVE-2026-15308 linked here
CVE-2026-59939 7.5 Bullseye, Matrix, Silk new python
CVE-2026-30922 7.5 Library not_applicable python → CVE-2026-59884
CVE-2026-59886 7.5 Library not_applicable python → CVE-2026-59884
CVE-2026-7246 7.2 Silk does_not_affect python

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Other CVEs related to this one as primary:

Related CVENoteTickets
CVE-2026-7210 same product as CVE-2026-15308 morris, mufasa, Library, Matrix, Archive, Saiph

Host OS / kernel

OS
CloudLinux release 7.9 (Boris Yegorov) (7.9) · cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64
kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
morris accepted_risk 7.0 2026-08-22T10:15:33Z Open
Library accepted_risk 1.75 2026-08-22T10:15:33Z Open
Matrix accepted_risk 1.75 2026-08-22T10:15:33Z Open
Archive accepted_risk 0.62 2026-08-22T10:15:33Z Open
Saiph accepted_risk 0.62 2026-08-22T10:15:33Z Open

Description

The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data.

Determination

CPU denial-of-service
Vulnerable Python present: Yes (2.7 + several 3.x)
Application code using html.parser on untrusted input: No evidence found
Overall practical risk: Low

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-02T20:06:59Z — affects
CPU denial-of-service
2026-08-02T20:07:41Z
TuxCare did backport a fix for this CVE to the system Python 2.7 package on EL7 (python-2.7.5-...tuxcare.els12). However, you are using the separate alt-python27 packages (CloudLinux Alternative Python 2.7.18). There is no evidence that these packages have received the corresponding security update for CVE-2026-15308.
2026-08-02T20:08:25Z
Recommendation: Check if a newer alt-python27 package is available from CloudLinux/cPanel repositories. If not, consider whether any applications still require this old Python 2.7 runtime, as it is long past end-of-life.
2026-08-04T19:00:34Z — accepted_risk
Vulnerable Python present: Yes (2.7 + several 3.x) Application code using html.parser on untrusted input: No evidence found Overall practical risk: Low

References

NVD: CVE-2026-15308