CVE-2026-85999

Source
https://cve.org/CVERecord?id=CVE-2026-85999
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85999.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85999
Aliases
Downstream
Published
2026-09-17T15:23:37Z
Modified
2026-09-18T03:48:32Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Details

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1333",
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85999.json"
}
References

Affected packages

Git / github.com/facelessuser/soupsieve

Affected ranges

Type
GIT
Repo
https://github.com/facelessuser/soupsieve
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.9"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
1.*
1.0.0
1.0.0b1
1.0.0b2
1.0.1
1.0.2
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.*
2.0.0
2.0.1
2.1.0
2.2
2.2.1
2.3
2.3.1
2.3.2
2.3.2.post1
2.4
2.4.1
2.5
2.6
2.7
2.8
2.8.1
2.8.2
2.8.3
2.8.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85999.json"