<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:14:13 +0000</lastBuildDate>
    <item>
      <title>BREW-adr-viewer-CVE-2026-49476 — Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
      <link>https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-49476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: adr-viewer&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup&amp;#39;s `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.&lt;/p&gt;
&lt;p&gt;A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106&lt;/p&gt;
&lt;p&gt;The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.&lt;/p&gt;
&lt;p&gt;When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:&lt;/p&gt;
&lt;p&gt;1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: adr-viewer&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup&amp;#39;s `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.&lt;/p&gt;
&lt;p&gt;A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106&lt;/p&gt;
&lt;p&gt;The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.&lt;/p&gt;
&lt;p&gt;When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:&lt;/p&gt;
&lt;p&gt;1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-49476</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BC02149 — Security fixes in airflow-3 3.1.8-r6</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</guid>
    </item>
    <item>
      <title>EUVD-2026-337997</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337997</link>
      <description>EUVD-2026-337997</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337997</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49476</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49476</link>
      <description>&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49476</guid>
    </item>
    <item>
      <title>GHSA-2wc2-fm75-p42x — Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2wc2-fm75-p42x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: soupsieve&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup&amp;#39;s `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.&lt;/p&gt;
&lt;p&gt;A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106&lt;/p&gt;
&lt;p&gt;The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.&lt;/p&gt;
&lt;p&gt;When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:&lt;/p&gt;
&lt;p&gt;1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: soupsieve&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup&amp;#39;s `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.&lt;/p&gt;
&lt;p&gt;A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106&lt;/p&gt;
&lt;p&gt;The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.&lt;/p&gt;
&lt;p&gt;When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:&lt;/p&gt;
&lt;p&gt;1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2wc2-fm75-p42x</guid>
    </item>
    <item>
      <title>OESA-2026-3619 — python-soupsieve security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-soupsieve&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. It aims to provide selecting, matching, and filtering using modern CSS selectors. Soup Sieve currently provides selectors from the CSS level 1 specifications up through the latest CSS level 4 drafts and beyond (though some are not yet implemented).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49476)&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49477)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: python-soupsieve&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. It aims to provide selecting, matching, and filtering using modern CSS selectors. Soup Sieve currently provides selectors from the CSS level 1 specifications up through the latest CSS level 4 drafts and beyond (though some are not yet implemented).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49476)&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.(CVE-2026-49477)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3619</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21342-1 — Security update for python-soupsieve</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21342-1</link>
      <description>&lt;p&gt;Security update for python-soupsieve&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-soupsieve&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21342-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3071 — Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3071</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: soupsieve&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup&amp;#39;s `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.&lt;/p&gt;
&lt;p&gt;A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106&lt;/p&gt;
&lt;p&gt;The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.&lt;/p&gt;
&lt;p&gt;When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:&lt;/p&gt;
&lt;p&gt;1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: soupsieve&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup&amp;#39;s `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately.&lt;/p&gt;
&lt;p&gt;A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106&lt;/p&gt;
&lt;p&gt;The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata.&lt;/p&gt;
&lt;p&gt;When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser:&lt;/p&gt;
&lt;p&gt;1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106)
2. Parses each segment into a full `Selector` object with all associated metadata (line ~925)
3. Stores all pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3071</guid>
    </item>
    <item>
      <title>RHSA-2026:34119 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:34119</link>
      <description>&lt;p&gt;urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers python-idna: idna: Denial of Service via specially crafted long inputs python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers python-idna: idna: Denial of Service via specially crafted long inputs python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:34119</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22660-1 — Security update for python-soupsieve</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22660-1</link>
      <description>&lt;p&gt;Security update for python-soupsieve&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-soupsieve&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22660-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49476</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: soupsieve, Ubuntu:22.04:LTS: soupsieve, Ubuntu:24.04:LTS: soupsieve, Ubuntu:26.04:LTS: soupsieve&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: soupsieve, Ubuntu:22.04:LTS: soupsieve, Ubuntu:24.04:LTS: soupsieve, Ubuntu:26.04:LTS: soupsieve&lt;/p&gt;
&lt;p&gt;Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49476</guid>
    </item>
  </channel>
</rss>
