CVE-2025-6069

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
PSFCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Debian logo
Debian Releases
Debian Product
Codename
jython
bullseye
postponed
trixie
no-dsa
bookworm
no-dsa
forky
vulnerable
sid
vulnerable
pypy3
bullseye
postponed
trixie
no-dsa
bookworm
no-dsa
bullseye (security)
7.3.5+dfsg-2+deb11u5
fixed
forky
vulnerable
sid
vulnerable
python2.7
bullseye
vulnerable
trixie
no-dsa
bookworm
no-dsa
python3.11
bookworm
no-dsa
trixie
no-dsa
bullseye
postponed
bookworm (security)
vulnerable
python3.13
trixie
no-dsa
bookworm
no-dsa
bullseye
postponed
forky
3.13.11-1
fixed
sid
3.13.11-1
fixed
python3.9
bullseye
postponed
trixie
no-dsa
bookworm
no-dsa
bullseye (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jython
questing
needs-triage
plucky
needs-triage
oracular
ignored
noble
needs-triage
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
python2.7
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
needed
focal
needed
bionic
needed
xenial
needed
trusty
needed
python3.11
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
Fixed 3.11.0~rc1-1~22.04.1~esm5
released
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.12
questing
dne
plucky
dne
oracular
ignored
noble
Fixed 3.12.3-1ubuntu0.8
released
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.13
questing
Fixed 3.13.6-1
released
plucky
Fixed 3.13.3-1ubuntu0.3
released
oracular
ignored
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.9
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
Fixed 3.9.5-3ubuntu0~20.04.1+esm6
released
bionic
dne
xenial
dne
trusty
dne
python3.4
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
Fixed 3.4.3-1ubuntu1~14.04.7+esm16
released
python3.5
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm19
released
trusty
Fixed 3.5.2-2ubuntu0~16.04.4~14.04.1+esm7
released
python3.6
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
Fixed 3.6.9-1~18.04ubuntu1.13+esm6
released
xenial
dne
trusty
dne
python3.7
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
Fixed 3.7.5-2ubuntu1~18.04.2+esm7
released
xenial
dne
trusty
dne
python3.8
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
Fixed 3.8.10-0ubuntu1~20.04.18+esm2
released
bionic
Fixed 3.8.0-3ubuntu1~18.04.2+esm6
released
xenial
dne
trusty
dne
python3.10
questing
dne
plucky
dne
oracular
dne
noble
dne
jammy
Fixed 3.10.12-1~22.04.11
released
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.14
questing
not-affected
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
dne