CVE-2026-15308 @ mufasa
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| python-2.7.5-94.0.5.el7_9.tuxcare.els1 | |
| python-augeas-0.5.0-2.el7 | |
| python-babel-0.9.6-8.el7 | |
| python-backports-1.0-8.el7 | |
| python-backports-ssl_match_hostname-3.5.0.1-1.el7 | |
| python-chardet-2.2.1-3.el7 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: python · python-augeas · python-babel · python-backports · python-backports-ssl_match_hostname · python-chardet
| System | Matches | Ticket for CVE-2026-15308 | |
|---|---|---|---|
| mufasa | python-augeas 0.5.0 | accepted_risk open |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-68770 | 9.8 | morris, mufasa | does_not_affect | python | — | ||
| CVE-2026-3644 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk, does_not_affect | python-chardet | — | ||
| CVE-2026-4224 | 7.5 | Archive, Library, Saiph, morris, mufasa | accepted_risk, does_not_affect | python-chardet | — | ||
| CVE-2026-7210 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk, not_applicable | python-chardet | → CVE-2026-15308 | linked here | |
| CVE-2026-59939 | 7.5 | Bullseye, Matrix, Silk | new | python | — | ||
| CVE-2026-30922 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-59886 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-7246 | 7.2 | Silk | does_not_affect | python | — |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Other CVEs related to this one as primary:
| Related CVE | Note | Tickets |
|---|---|---|
| CVE-2026-7210 | same product as CVE-2026-15308 | morris, mufasa, Library, Matrix, Archive, Saiph |
Host OS / kernel
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | accepted_risk | 7.0 | 2026-08-22T10:15:33Z | Open |
| Library | accepted_risk | 1.75 | 2026-08-22T10:15:33Z | Open |
| Matrix | accepted_risk | 1.75 | 2026-08-22T10:15:33Z | Open |
| Archive | accepted_risk | 0.62 | 2026-08-22T10:15:33Z | Open |
| Saiph | accepted_risk | 0.62 | 2026-08-22T10:15:33Z | Open |
Description
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
Determination
CPU denial-of-service Vulnerable Python present: Yes (2.7 + several 3.x) Application code using html.parser on untrusted input: No evidence found Overall practical risk: Low
Update status
Add note only
Mitigation log
References
- https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9
- https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7
- https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14
- https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced
- https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606
- https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00
- https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd
- https://github.com/python/cpython/issues/153030
- https://github.com/python/cpython/pull/153031
- https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/
- http://www.openwall.com/lists/oss-security/2026/07/09/4
NVD: CVE-2026-15308