PT-2026-94387 · Pypi · Beautiful Soup+1

·

CVE-2026-86000

·

Published

2026-09-06

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Soup Sieve versions prior to 2.9
Description A Regular Expression Denial of Service (ReDoS) exists in the selector parser located in src/soupsieve/css parser.py. The IDENTIFIER pattern uses adjacent quantified groups over overlapping character classes, and the VALUE pattern embeds IDENTIFIER for attribute selectors. When a user-controlled selector contains a long identifier or an unquoted attribute-value run followed by input that causes the match to fail, the regular expression engine performs quadratic backtracking. This can be triggered via soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(). The resulting high CPU consumption can hold the Python Global Interpreter Lock (GIL), exhaust application workers, and stall the service. Applications using only hard-coded selectors are not affected.
Recommendations Update Soup Sieve to version 2.9. As a temporary mitigation, restrict the maximum length of user-supplied CSS selectors before they are passed to the parser.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103325
BDU:2026-15029
CVE-2026-86000
ECHO-7D38-76D0-5832
GHSA-GJV8-XP57-G29C
OPENSUSE-SU-2026:11866-1
SUSE-SU-2026:4365-1

Affected Products

Beautiful Soup
Soupsieve