{"id":"OESA-2026-3620","summary":"python-soupsieve security update","details":"Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. It aims to provide selecting, matching, and filtering using modern CSS selectors. Soup Sieve currently provides selectors from the CSS level 1 specifications up through the latest CSS level 4 drafts and beyond (though some are not yet implemented).\r\n\r\nSecurity Fix(es):\n\nSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49476)\n\nSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49477)","modified":"2026-09-05T15:16:23.315108807Z","published":"2026-09-05T15:03:13Z","upstream":["CVE-2026-49476","CVE-2026-49477"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3620"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49476"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49477"}],"affected":[{"package":{"name":"python-soupsieve","ecosystem":"openEuler:24.03-LTS-SP1","purl":"pkg:rpm/openEuler/python-soupsieve&distro=openEuler-24.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4-2.oe2403sp1"}]}],"ecosystem_specific":{"noarch":["python3-soupsieve-2.4-2.oe2403sp1.noarch.rpm"],"src":["python-soupsieve-2.4-2.oe2403sp1.src.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3620.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}