Vulnerability Description
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end of the sibling list, such as with `[last()]` or `[last()-N]`; `.//item[1]` short-circuits after the first match.
Related Weaknesses (CWE)
References
- https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f8
- https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b
- https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8d
- https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f0
- https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c
- https://github.com/python/cpython/issues/152674
- https://github.com/python/cpython/pull/152676
- https://mail.python.org/archives/list/[email protected]/thread/7YMZ6D
FAQ
What is CVE-2026-6879?
CVE-2026-6879 is a documented vulnerability. `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-ta...
How severe is CVE-2026-6879?
CVSS scoring is not yet available for CVE-2026-6879. Check NVD for updates.
Is there a patch for CVE-2026-6879?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.