PT-2026-94386 · Pypi · Beautiful Soup+1

·

CVE-2026-85999

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Soup Sieve versions prior to 2.9
Description An issue exists in the selector iter function within src/soupsieve/css parser.py where the raw selector is trimmed using RE WS END. Because this regular expression is anchored only at the end and used with search(), the engine performs a greedy scan at every starting offset. A valid selector containing a long internal whitespace run or a long CSS comment run followed by another token triggers quadratic CPU work. This can be exploited via soupsieve.compile() and BeautifulSoup.select(). The resulting CPU consumption can hold the Python Global Interpreter Lock (GIL), exhaust workers, and stall services, leading to a Denial of Service (DoS). Applications using only hard-coded selectors are not affected.
Recommendations Update Soup Sieve to version 2.9. As a temporary mitigation, cap the maximum length of user-supplied CSS selectors before they are compiled.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103322
CVE-2026-85999
ECHO-DFDF-DD36-A3ED
GHSA-J934-XHV5-FG8F
OPENSUSE-SU-2026:11866-1
SUSE-SU-2026:4365-1

Affected Products

Beautiful Soup
Soupsieve