<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:40:42.572442+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-49477</id>
    <title>BREW-adr-viewer-CVE-2026-49477 — Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser</title>
    <updated>2026-10-02T13:40:42.829768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: adr-viewer</p>
<p>### Summary</p>
<p>The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponential backtracking. A payload of only **300 bytes** causes the regex engine to hang for **over 3 seconds**, enabling a trivial Regular Expression Denial of Service (ReDoS) attack.</p>
<p>To be completely transparent, AI tools helped surface this issue. However, this was independently reproduced and carefully validated.</p>
<p>Any application that passes untrusted CSS selector strings to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` is affected.</p>
<p>### Details</p>
<p>**Affected code:** `soupsieve/css_parser.py`, line ~121 - `RE_VALUES` / `VALUE` regex pattern</p>
<p>The soupsieve CSS parser uses a compiled regular expression to tokenise attribute selector values. This pattern matches both quoted strings (`"value"` or `'value'`) and unquoted identifiers. The regex contains alternation branches for:</p>
<p>1. Double-quoted strings: `"[^"\\]*(?:\\.[^"\\]*)*"`
2. Single-quoted strings: `'[^'\\]*(?:\\.[^'\\]*)*'`
3. Unquoted identifiers</p>
<p>When an attribute selector contains an **unterminated quoted value** - e.g., `[a="xxxx...` (opening `"` but no closing `"`) -” the regex engine attempts to match the quoted-string branch. After that branch fails (no closing quote), the engine backtracks and at…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-49477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:40:42.829899+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</id>
    <title>Withdrawn: CLEANSTART-2026-BC02149 — Security fixes in airflow-3 3.1.8-r6</title>
    <updated>2026-10-02T13:40:42.829928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339159</id>
    <title>EUVD-2026-339159</title>
    <updated>2026-10-02T13:40:42.829967+00:00</updated>
    <content>EUVD-2026-339159</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49477</id>
    <title>fkie_cve-2026-49477</title>
    <updated>2026-10-02T13:40:42.829995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-836r-79rf-4m37</id>
    <title>GHSA-836r-79rf-4m37 — Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser</title>
    <updated>2026-10-02T13:40:42.830032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: soupsieve</p>
<p>### Summary</p>
<p>The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponential backtracking. A payload of only **300 bytes** causes the regex engine to hang for **over 3 seconds**, enabling a trivial Regular Expression Denial of Service (ReDoS) attack.</p>
<p>To be completely transparent, AI tools helped surface this issue. However, this was independently reproduced and carefully validated.</p>
<p>Any application that passes untrusted CSS selector strings to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` is affected.</p>
<p>### Details</p>
<p>**Affected code:** `soupsieve/css_parser.py`, line ~121 - `RE_VALUES` / `VALUE` regex pattern</p>
<p>The soupsieve CSS parser uses a compiled regular expression to tokenise attribute selector values. This pattern matches both quoted strings (`"value"` or `'value'`) and unquoted identifiers. The regex contains alternation branches for:</p>
<p>1. Double-quoted strings: `"[^"\\]*(?:\\.[^"\\]*)*"`
2. Single-quoted strings: `'[^'\\]*(?:\\.[^'\\]*)*'`
3. Unquoted identifiers</p>
<p>When an attribute selector contains an **unterminated quoted value** - e.g., `[a="xxxx...` (opening `"` but no closing `"`) -” the regex engine attempts to match the quoted-string branch. After that branch fails (no closing quote), the engine backtracks and at…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-836r-79rf-4m37"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3619</id>
    <title>OESA-2026-3619 — python-soupsieve security update</title>
    <updated>2026-10-02T13:40:42.830095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: python-soupsieve</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. It aims to provide selecting, matching, and filtering using modern CSS selectors. Soup Sieve currently provides selectors from the CSS level 1 specifications up through the latest CSS level 4 drafts and beyond (though some are not yet implemented).

Security Fix(es):</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49476)</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49477)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3619"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21342-1</id>
    <title>openSUSE-SU-2026:21342-1 — Security update for python-soupsieve</title>
    <updated>2026-10-02T13:40:42.830125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-soupsieve</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21342-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3072</id>
    <title>PYSEC-2026-3072 — Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser</title>
    <updated>2026-10-02T13:40:42.830154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: soupsieve</p>
<p>### Summary</p>
<p>The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponential backtracking. A payload of only **300 bytes** causes the regex engine to hang for **over 3 seconds**, enabling a trivial Regular Expression Denial of Service (ReDoS) attack.</p>
<p>To be completely transparent, AI tools helped surface this issue. However, this was independently reproduced and carefully validated.</p>
<p>Any application that passes untrusted CSS selector strings to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` is affected.</p>
<p>### Details</p>
<p>**Affected code:** `soupsieve/css_parser.py`, line ~121 - `RE_VALUES` / `VALUE` regex pattern</p>
<p>The soupsieve CSS parser uses a compiled regular expression to tokenise attribute selector values. This pattern matches both quoted strings (`"value"` or `'value'`) and unquoted identifiers. The regex contains alternation branches for:</p>
<p>1. Double-quoted strings: `"[^"\\]*(?:\\.[^"\\]*)*"`
2. Single-quoted strings: `'[^'\\]*(?:\\.[^'\\]*)*'`
3. Unquoted identifiers</p>
<p>When an attribute selector contains an **unterminated quoted value** - e.g., `[a="xxxx...` (opening `"` but no closing `"`) -” the regex engine attempts to match the quoted-string branch. After that branch fails (no closing quote), the engine backtracks and at…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34119</id>
    <title>RHSA-2026:34119 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T13:40:42.830263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers python-idna: idna: Denial of Service via specially crafted long inputs python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22660-1</id>
    <title>SUSE-SU-2026:22660-1 — Security update for python-soupsieve</title>
    <updated>2026-10-02T13:40:42.830304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-soupsieve</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22660-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49477</id>
    <title>UBUNTU-CVE-2026-49477</title>
    <updated>2026-10-02T13:40:42.830364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: soupsieve, Ubuntu:22.04:LTS: soupsieve, Ubuntu:24.04:LTS: soupsieve, Ubuntu:26.04:LTS: soupsieve</p>
<p>Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49477"/>
  </entry>
</feed>
