CVE-2026-49476Disclosure(facelessuser / soup_sieve)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • soup_sieve

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
soup_sieve

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Unbounded memory allocation in soupsieve selector compilation (CVE-2026-49476) soupsieve’s CSS selector parser can allocate unbounded memory when compiling very large comma-separated selector lists, impacting soupsieve.compile() and Beautiful Soup’s select/select_one paths that rely on soupsieve. The root cause is improper input validation/resource management: there’s no limit on how many selectors are parsed and stored, enabling heap allocation amplification. An attacker can exploit this by supplying a crafted selector string to any application endpoint or feature that accepts user-controlled CSS selectors and passes them into soupsieve/Beautiful Soup, with no special privileges required beyond reaching that code path. Successful exploitation results in severe memory exhaustion leading to denial of service and potential process/container instability. 👉 Affected: soupsieve (versions with no selector-count limits; see vendor advisory for exact range) | Upgrade to No fix yet — treat as suspicious

    Post summary

    A new CVE (CVE-2026-49476) reveals unbounded memory allocation in soupsieve’s selector parsing that can cause DoS, with no fix available yet.

    0000090
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfacelessusersoup_sieve-beautiful_soup-

Explore more