CVE-2025-12084

Updated: 2025-12-28 04:13:26.790883

Description:

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 python 3.6 5.3 MEDIUM Needs Triage 2025-12-28 07:12:36
Debian 10 python 2.7 5.3 MEDIUM Needs Triage 2025-12-28 07:12:44
Debian 11 python 2.7 5.3 MEDIUM Needs Triage 2025-12-28 07:12:45
Debian 11 python 3.6 5.3 MEDIUM Needs Triage 2025-12-28 07:12:41
Debian 12 python 3.9 5.3 MEDIUM In Testing 2026-01-09 13:25:05
Debian 12 python 3.7 5.3 MEDIUM In Progress 2026-01-09 13:25:03
Debian 12 python 3.6 5.3 MEDIUM In Testing 2026-01-08 15:46:24
Debian 12 python 2.7 5.3 MEDIUM Needs Triage 2025-12-28 07:12:46
Debian 12 python 3.8 5.3 MEDIUM In Testing 2026-01-09 13:25:02
Debian 13 python 3.9 5.3 MEDIUM In Testing 2026-01-09 13:25:04
Total: 32