Impact
Soup Sieve contains a regular‑expression denial of service in the whitespace/comment trimming regex RE_WS_END. The greedy scan causes quadratic CPU consumption when a selector string includes a long run of whitespace or CSS comments. This high CPU load can hold the Python GIL, exhaust workers, and stall a service, although it does not corrupt memory or execute code.
Affected Systems
Soupsieve library versions earlier than 2.9 are affected. Applications that use Soupsieve through BeautifulSoup.select() and accept user‑controlled selector strings are vulnerable, while those that use only hard‑coded selectors remain unaffected.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. An attacker can exploit the flaw by submitting a crafted selector with a long run of whitespace or comments to soupsieve.compile() or BeautifulSoup.select(), achieving Denial of Service by exhausting CPU resources.
OpenCVE Enrichment
Github GHSA