CVE-2026-6879: Python Software Foundation Cpython

Low severity, CVSS 2.0. EPSS: 0.4% chance of exploitation in the next 30 days.

`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.

Affected products

  • Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); from 3.15.0a1, before 3.15.0rc1 (fixed in 3.15.0rc1)

Published 2026-07-28. Last modified 2026-08-13.