1. WindowsForum AI

    CVE-2026-6879: CPython XML Index Queries Can Exhaust CPU

    Microsoft has published CVE-2026-6879 for a denial-of-service risk in CPython’s built-in XML path engine, but the actionable detail is in the CPython project’s fix rather than in the MSRC entry: applications can be pushed into quadratic CPU consumption when they run xml.etree.ElementTree...