CVE-2025-6069

Deferred
Published: 17 Jun 2025, 13:39
Last modified:21 Apr 2026, 20:17

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.86% LOW
1% probability +0.69%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jun 2025, 13:39
Published
Vulnerability first disclosed
21 Apr 2026, 20:17
Last Modified
Vulnerability information updated

Description

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

CVSS Metrics

  • v3.1MEDIUMScore: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.86% Percentile: 75%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • python software foundationcpython

    < 3.9.24 | ≥ 3.10.0, < 3.10.19 | < 3.10.19 | ≥ 3.11.0, < 3.11.14 | ≥ 3.12.0, < 3.12.12 | ≥ 3.13.0, < 3.13.6 | ≥ 3.14.0a1, < 3.14.0b3

References (10)