<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:44:13.739255+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-49476</id>
    <title>BREW-adr-viewer-CVE-2026-49476 — Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
    <updated>2026-10-04T01:44:14.244400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: adr-viewer</p>
<p>### Summary</p>
<p>The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.</p>
<p>To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.</p>
<p>A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.</p>
<p>### Details</p>
<p>**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106</p>
<p>The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.</p>
<p>When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:</p>
<p>1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-49476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T01:44:14.244574+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</id>
    <title>Withdrawn: CLEANSTART-2026-BC02149 — Security fixes in airflow-3 3.1.8-r6</title>
    <updated>2026-10-04T01:44:14.244611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337997</id>
    <title>EUVD-2026-337997</title>
    <updated>2026-10-04T01:44:14.244652+00:00</updated>
    <content>EUVD-2026-337997</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49476</id>
    <title>fkie_cve-2026-49476</title>
    <updated>2026-10-04T01:44:14.244674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2wc2-fm75-p42x</id>
    <title>GHSA-2wc2-fm75-p42x — Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
    <updated>2026-10-04T01:44:14.244710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: soupsieve</p>
<p>### Summary</p>
<p>The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.</p>
<p>To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.</p>
<p>A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.</p>
<p>### Details</p>
<p>**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106</p>
<p>The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.</p>
<p>When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:</p>
<p>1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2wc2-fm75-p42x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3619</id>
    <title>OESA-2026-3619 — python-soupsieve security update</title>
    <updated>2026-10-04T01:44:14.244810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: python-soupsieve</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. It aims to provide selecting, matching, and filtering using modern CSS selectors. Soup Sieve currently provides selectors from the CSS level 1 specifications up through the latest CSS level 4 drafts and beyond (though some are not yet implemented).

Security Fix(es):</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49476)</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49477)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3619"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21342-1</id>
    <title>openSUSE-SU-2026:21342-1 — Security update for python-soupsieve</title>
    <updated>2026-10-04T01:44:14.244880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-soupsieve</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21342-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3071</id>
    <title>PYSEC-2026-3071 — Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
    <updated>2026-10-04T01:44:14.244917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: soupsieve</p>
<p>### Summary</p>
<p>The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.</p>
<p>To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.</p>
<p>A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.</p>
<p>### Details</p>
<p>**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106</p>
<p>The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.</p>
<p>When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:</p>
<p>1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34119</id>
    <title>RHSA-2026:34119 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T01:44:14.245006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers python-idna: idna: Denial of Service via specially crafted long inputs python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22660-1</id>
    <title>SUSE-SU-2026:22660-1 — Security update for python-soupsieve</title>
    <updated>2026-10-04T01:44:14.245046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-soupsieve</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22660-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49476</id>
    <title>UBUNTU-CVE-2026-49476</title>
    <updated>2026-10-04T01:44:14.245079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: soupsieve, Ubuntu:22.04:LTS: soupsieve, Ubuntu:24.04:LTS: soupsieve, Ubuntu:26.04:LTS: soupsieve</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49476"/>
  </entry>
</feed>
