CVE-2025-6069

Aliases:UBUNTU-CVE-2025-6069DEBIAN-CVE-2025-6069CGA-3236-72wj-28wrCGA-98g7-xffj-f98qCGA-cv9c-jx2q-qw4cCGA-g8ph-pvgc-pcfrCGA-jwhm-r4qw-qq2rCGA-287m-v5v2-4rhqCGA-q553-jm4r-fvf6CGA-rh9v-vmw3-hj9fCGA-whqj-8prc-pfvqCGA-wrpf-p62r-53gp
Deferred
Published: 17 Jun 2025, 13:39
Last modified:31 Jul 2026, 14:01

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.59% LOW
1% probability +0.41%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jun 2025, 13:39
Published
Vulnerability first disclosed
31 Jul 2026, 14:01
Last Modified
Vulnerability information updated

Description

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

CVSS Metrics

  • v3.1MEDIUMScore: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 0.59% Percentile: 47%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • chainguardpython-3.10

    < 3.10.18-r1

  • chainguardpython-3.11

    < 3.11.13-r1

  • chainguardpython-3.12

    < 3.12.11-r1

  • chainguardpython-3.13

    < 3.13.5-r1

  • chainguardpython-3.9

    < 3.9.23-r1

  • wolfipython-3.10

    < 3.10.18-r1

  • wolfipython-3.11

    < 3.11.13-r1

  • wolfipython-3.12

    < 3.12.11-r1

  • wolfipython-3.13

    < 3.13.5-r1

  • debianjython

    all | all | all | all

  • debianpypy3

    < 7.3.5+dfsg-2+deb11u5 | all | all | < 7.3.21+dfsg-1

  • debianpython2.7

    all

  • debianpython3.11

    < 3.11.2-6+deb12u7

  • debianpython3.13

    < 3.13.5-2+deb13u1 | < 3.13.6-1

  • debianpython3.9

    < 3.9.2-1+deb11u4

  • ubuntujython

    all | all | all | all | all | all | all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    < 3.10.12-1~22.04.11

  • ubuntupython3.11

    < 3.11.0~rc1-1~22.04.1~esm5

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.8

  • ubuntupython3.13

    < 3.13.6-1

  • ubuntupython3.4

    < 3.4.3-1ubuntu1~14.04.7+esm16

  • ubuntupython3.5

    < 3.5.2-2ubuntu0~16.04.4~14.04.1+esm7 | < 3.5.2-2ubuntu0~16.04.13+esm19

  • ubuntupython3.6

    < 3.6.9-1~18.04ubuntu1.13+esm6

  • ubuntupython3.7

    < 3.7.5-2ubuntu1~18.04.2+esm7

  • ubuntupython3.8

    < 3.8.0-3ubuntu1~18.04.2+esm6 | < 3.8.10-0ubuntu1~20.04.18+esm2

  • ubuntupython3.9

    < 3.9.5-3ubuntu0~20.04.1+esm6

  • python software foundationcpython

    < 3.10.19 | < 3.9.24 | ≥ 3.10.0, < 3.10.19 | ≥ 3.11.0, < 3.11.14 | ≥ 3.12.0, < 3.12.12 | ≥ 3.13.0, < 3.13.6 | ≥ 3.14.0a1, < 3.14.0b3

References (17)