
🚨 HIGH - Unbounded memory allocation in soupsieve selector compilation (CVE-2026-49476) soupsieve’s CSS selector parser can allocate unbounded memory when compiling very large comma-separated selector lists, impacting soupsieve.compile() and Beautiful Soup’s select/select_one paths that rely on soupsieve. The root cause is improper input validation/resource management: there’s no limit on how many selectors are parsed and stored, enabling heap allocation amplification. An attacker can exploit this by supplying a crafted selector string to any application endpoint or feature that accepts user-controlled CSS selectors and passes them into soupsieve/Beautiful Soup, with no special privileges required beyond reaching that code path. Successful exploitation results in severe memory exhaustion leading to denial of service and potential process/container instability. 👉 Affected: soupsieve (versions with no selector-count limits; see vendor advisory for exact range) | Upgrade to No fix yet — treat as suspicious
Post summary
A new CVE (CVE-2026-49476) reveals unbounded memory allocation in soupsieve’s selector parsing that can cause DoS, with no fix available yet.
