OESA-2026-3621
Dashboard / Vulnerabilities / OESA-2026-3621
OESA-2026-3621
Summary: python-soupsieve security update
Details: Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. It aims to provide selecting, matching, and filtering using modern CSS selectors. Soup Sieve currently provides selectors from the CSS level 1 specifications up through the latest CSS level 4 drafts and beyond (though some are not yet implemented). Security Fix(es): Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49476) Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49477)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3621, https://nvd.nist.gov/vuln/detail/CVE-2026-49476, https://nvd.nist.gov/vuln/detail/CVE-2026-49477
Affected packages
Package
Name: python-soupsieve
Purl: pkg:rpm/openEuler/python-soupsieve&distro=openEuler-24.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
