[CLSA-2026:1784713635] python3: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-22 09:47:40 UTC
Description:
- CVE-2026-15308: fix quadratic complexity (denial of service) in incremental parsing in html.parser.HTMLParser when an unterminated construct is fed across many feed() calls
CVEs fixed:
Updated packages:
  • python3-3.7.16-1.amzn2.0.26.tuxcare.els2.i686.rpm
    sha:21b4c9ce61acc5c95cc344a1c330c9b3f8cef9493dd088abdf5d86130cfb5d54
  • python3-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:18b4aee7c8e93d0a96872b7bfe3bbdc4471003bda59aa53a8cafcad0d4b8a5a1
  • python3-debug-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:24da195ee49acd3fe49b5857de1ea509d3b5c2be795e2e86174852625b267566
  • python3-devel-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:9ceddee15e6224708c890bfd025fd5ccbf029e7dd277a3e3ae458b780b723af4
  • python3-libs-3.7.16-1.amzn2.0.26.tuxcare.els2.i686.rpm
    sha:88dc1bc65acf0d979becf2d9685bb475459d0b92eec93cfaa99525dafdc20a79
  • python3-libs-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:f65cfe57f0841276140598639d6f611c4660a1ea6d41a0d25c73eed225219179
  • python3-test-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:a4a11149c5b7f06a94386027c869adda0892b12a4cae85357bcf2ab40eefe1ef
  • python3-tkinter-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:03566987bf4ab3b87610bebc56d800a63db9d0aee43b87bbabeab9b7fb663832
  • python3-tools-3.7.16-1.amzn2.0.26.tuxcare.els2.x86_64.rpm
    sha:2544ba1ec4b191a9d1d55e93c5506e549fec3a5aed04cfc7a83c57f2e01266f7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.