Описание
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.
A flaw was found in soupsieve, a CSS selector library used with Beautiful Soup 4. This vulnerability allows a remote attacker to cause a denial of service (DoS) by supplying a specially crafted CSS selector string. The parser allocates unbounded memory when compiling large, comma-separated selector lists, leading to excessive memory consumption and system instability.
Отчет
An uncontrolled resource consumption vulnerability was found in the soupsieve Python package, a CSS selector library used by BeautifulSoup4. A remote attacker could provide a crafted CSS selector string that causes excessive memory or CPU consumption, leading to a denial of service condition. It requires the application to accept untrusted CSS selectors supplied in one of the following sinks:
- soupsieve.compile()
- BeautifulSoup.select()
- BeautifulSoup.select_one() This is an uncommon scenario.
Меры по смягчению последствий
There is no mitigation for this flaw other than updating the soupsieve package when upstream patches are available. The impact is limited to availability (denial of service) — an attacker cannot access or modify data through this vulnerability. Applications that do not process untrusted CSS selector strings are at reduced risk.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Fix deferred | ||
| Migration Toolkit for Applications 8 | mta/mta-solution-server-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-ocp-rag-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 | Fix deferred | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-chatbot-rhel8 | Fix deferred | ||
| Red Hat Hardened Images | python-urllib3 | Not affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-automl-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-autorag-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.
Soup Sieve is a CSS selector library designed to be used with Beautifu ...
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
EPSS
5.9 Medium
CVSS3