Pypi · Beautiful Soup · CVE-2026-86000
**Name of the Vulnerable Software and Affected Versions**
Soup Sieve versions prior to 2.9
**Description**
A Regular Expression Denial of Service (ReDoS) exists in the selector parser located in `src/soupsieve/css parser.py`. The `IDENTIFIER` pattern uses adjacent quantified groups over overlapping character classes, and the `VALUE` pattern embeds `IDENTIFIER` for attribute selectors. When a user-controlled selector contains a long identifier or an unquoted attribute-value run followed by input that causes the match to fail, the regular expression engine performs quadratic backtracking. This can be triggered via `soupsieve.compile()`, `soupsieve.select()`, or `BeautifulSoup.select()`. The resulting high CPU consumption can hold the Python Global Interpreter Lock (GIL), exhaust application workers, and stall the service. Applications using only hard-coded selectors are not affected.
**Recommendations**
Update Soup Sieve to version 2.9.
As a temporary mitigation, restrict the maximum length of user-supplied CSS selectors before they are passed to the parser.