CVE-2025-12084

Updated: 2026-02-04 05:06:15.577937

Description:

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Alpine Linux 3.22 python 3.9 5.3 MEDIUM Released CLSA-2026:1770035228 2026-02-02 14:29:59
Alpine Linux 3.22 python 3.7 5.3 MEDIUM Released CLSA-2026:1771329661 2026-02-17 15:44:51
Alpine Linux 3.22 python 3.8 5.3 MEDIUM Released CLSA-2026:1770316296 2026-02-07 04:07:42
Alpine Linux 3.22 python 3.6 5.3 MEDIUM Released CLSA-2026:1769524909 2026-01-27 16:43:25
Debian 10 python 3.6 5.3 MEDIUM Released CLSA-2026:1771342739 2026-02-20 19:27:47
Debian 10 python 2.7 5.3 MEDIUM In Testing 2026-02-20 09:22:11
Debian 11 python 2.7 5.3 MEDIUM In Testing 2026-02-20 09:22:11
Debian 11 python 3.6 5.3 MEDIUM Released CLSA-2026:1771342958 2026-02-20 19:27:46
Debian 12 python 3.9 5.3 MEDIUM Released CLSA-2026:1768569080 2026-01-16 15:37:45
Debian 12 python 3.7 5.3 MEDIUM Released CLSA-2026:1768571053 2026-01-16 15:37:41
Total: 36