PT-2026-94387 · Pypi · Beautiful Soup+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Soup Sieve versions prior to 2.9
Description
A Regular Expression Denial of Service (ReDoS) exists in the selector parser located in
src/soupsieve/css parser.py. The IDENTIFIER pattern uses adjacent quantified groups over overlapping character classes, and the VALUE pattern embeds IDENTIFIER for attribute selectors. When a user-controlled selector contains a long identifier or an unquoted attribute-value run followed by input that causes the match to fail, the regular expression engine performs quadratic backtracking. This can be triggered via soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(). The resulting high CPU consumption can hold the Python Global Interpreter Lock (GIL), exhaust application workers, and stall the service. Applications using only hard-coded selectors are not affected.Recommendations
Update Soup Sieve to version 2.9.
As a temporary mitigation, restrict the maximum length of user-supplied CSS selectors before they are passed to the parser.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Beautiful Soup
Soupsieve