Back to overview

CVE-2026-6879

LOW
2.0
CVSS 4.0
Description
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match.

Metadata

CVE ID
CVE-2026-6879
State
PUBLISHED
Assigner
PSF
Reserved
2026-04-22 18:26 UTC
Published
2026-07-28 13:46 UTC
Last updated
2026-07-28 14:54 UTC
Primary CWE
CWE-407
CWE-407 Inefficient Algorithmic Complexity
Vendor / Product
Python Software Foundation / CPython
Sources
cve.org  ·  NVD

Severity & Metrics

2.0 LOW CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Python Software Foundation CPython 0 < 3.15.0
Weakness (CWE)
CWESourceDescription
CWE-407 adp CWE-407 Inefficient Algorithmic Complexity
CVSS scores (1)
ScoreSeverityVersionSourceVector
2.0 LOW 4.0 cna CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Back to overview