Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49476

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.

A flaw was found in soupsieve, a CSS selector library used with Beautiful Soup 4. This vulnerability allows a remote attacker to cause a denial of service (DoS) by supplying a specially crafted CSS selector string. The parser allocates unbounded memory when compiling large, comma-separated selector lists, leading to excessive memory consumption and system instability.

Отчет

An uncontrolled resource consumption vulnerability was found in the soupsieve Python package, a CSS selector library used by BeautifulSoup4. A remote attacker could provide a crafted CSS selector string that causes excessive memory or CPU consumption, leading to a denial of service condition. It requires the application to accept untrusted CSS selectors supplied in one of the following sinks:

  • soupsieve.compile()
  • BeautifulSoup.select()
  • BeautifulSoup.select_one() This is an uncommon scenario.

Меры по смягчению последствий

There is no mitigation for this flaw other than updating the soupsieve package when upstream patches are available. The impact is limited to availability (denial of service) — an attacker cannot access or modify data through this vulnerability. Applications that do not process untrusted CSS selector strings are at reduced risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Fix deferred
Red Hat Hardened Imagespython-urllib3Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-automl-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-autorag-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2500715python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string

EPSS

Процентиль: 41%
0.00522
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.

CVSS3: 7.5
nvd
23 дня назад

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.

CVSS3: 7.5
debian
23 дня назад

Soup Sieve is a CSS selector library designed to be used with Beautifu ...

CVSS3: 7.5
github
28 дней назад

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

suse-cvrf
23 дня назад

Security update for python-soupsieve

EPSS

Процентиль: 41%
0.00522
Низкий

5.9 Medium

CVSS3