CVE-2026-86000: Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/cssparser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled selector contains a long identifier or unquoted attribute-value run followed by input that makes the overall match fail, the regular expression engine explores quadratically many splits between the overlapping groups. User-controlled selectors can reach this path through soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. The resulting CPU consumption can hold the Python GIL, exhaust application workers, and stall a service; successful plain identifier matches are linear, and the issue does not cause memory corruption or code execution. The issue is fixed in version 2.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
soup/soupsieveto a version that resolves this vulnerability.Fixed in 2.9
Event History
Frequently Asked Questions
Which applications are realistically exposed to this issue?
Applications are exposed when they pass attacker-controlled CSS selectors to soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(). Applications that use only hard-coded selectors are unaffected.
What input is needed to trigger excessive CPU use?
An attacker needs to supply a selector containing a long identifier or an unquoted attribute-value run, followed by input that causes the overall match to fail. Successful plain identifier matches are linear and do not trigger the quadratic behavior.
What is the operational impact of a successful attack?
The parser can consume CPU quadratically, hold the Python GIL, exhaust application workers, and stall the service. The issue does not provide memory corruption or code execution.
How can this be remediated?
Upgrade soupsieve to version 2.9, which fixes the issue.