Impact
Soup Sieve’s parser uses adjacent quantified regex groups that, when combined with long identifier or unquoted attribute-value strings, cause the engine to explore a quadratic number of splits. This polynomial‑time ReDoS consumes CPU resources, can hold the Python GIL, exhaust application workers and stall a service. The flaw does not lead to memory corruption or code execution, but it results in denial of function through excessive CPU usage.
Affected Systems
The vulnerability affects the Soup Sieve library provided by the open‑source project, specifically all releases prior to 2.9. Applications that invoke soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select() with externally supplied selectors are at risk. Hard‑coded selectors or libraries that never parse user data are not impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity; the EPSS score is not available, so the likelihood of exploitation is unclear, and the issue is not listed in CISA’s KEV catalog. An attacker can trigger the slowdown by sending a crafted selector string through any interface that accepts arbitrary CSS selectors, such as web forms or APIs that use BeautifulSoup.select().
OpenCVE Enrichment
Github GHSA