Description
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via CPU exhaustion
Action: Patch
AI Analysis

Impact

Soup Sieve contains a regular‑expression denial of service in the whitespace/comment trimming regex RE_WS_END. The greedy scan causes quadratic CPU consumption when a selector string includes a long run of whitespace or CSS comments. This high CPU load can hold the Python GIL, exhaust workers, and stall a service, although it does not corrupt memory or execute code.

Affected Systems

Soupsieve library versions earlier than 2.9 are affected. Applications that use Soupsieve through BeautifulSoup.select() and accept user‑controlled selector strings are vulnerable, while those that use only hard‑coded selectors remain unaffected.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. An attacker can exploit the flaw by submitting a crafted selector with a long run of whitespace or comments to soupsieve.compile() or BeautifulSoup.select(), achieving Denial of Service by exhausting CPU resources.

Generated by OpenCVE AI on September 17, 2026 at 20:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Soupsieve to version 2.9 or later
  • If an upgrade cannot be performed immediately, restrict Soupsieve usage to hard‑coded selectors and sanitize or validate user‑supplied selectors to remove long whitespace or comment runs
  • As an additional precaution, consider disabling selector functionality for untrusted input or switching to a selector library that does not use the vulnerable regex

Generated by OpenCVE AI on September 17, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j934-xhv5-fg8f Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
History

Tue, 22 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Facelessuser
Facelessuser soupsieve
Vendors & Products Facelessuser
Facelessuser soupsieve

Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9.
Title Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Weaknesses CWE-1333
CWE-400
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Facelessuser Soupsieve
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T20:29:44.838Z

Reserved: 2026-09-04T19:17:36.246Z

Link: CVE-2026-85999

cve-icon Vulnrichment

Updated: 2026-09-22T20:24:47.344Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:16.590

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-85999

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T15:23:37Z

Links: CVE-2026-85999 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity

  • CWE-400

    Uncontrolled Resource Consumption