CVE-2026-86000
Soup Sieve regex backtracking DoS via crafted CSS selector (pre‑2.9)
- CVSS 5.3
- 400
- Input Validation and Sanitization
- Remote
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled selector contains a long identifier or unquoted attribute-value run followed by input that makes the overall match fail, the regular expression engine explores quadratically many splits between the overlapping groups. User-controlled selectors can reach this path through soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. The resulting CPU consumption can hold the Python GIL, exhaust application workers, and stall a service; successful plain identifier matches are linear, and the issue does not cause memory corruption or code execution. The issue is fixed in version 2.9.
- CWE
- 400
- CVSS base score
- 5.3
- Published
- 2026-09-17
- OWASP
- A04 Insecure Design
- Orthogonal defect classification
- Algorithm
- Code defect classification
- Incorrect Algorithm
- Category
- Input Validation and Sanitization
- Subcategory
- Insecure Parsing or Deserialization
- Accessibility scope
- Remote
- Impact
- Denial of Service (DoS)
- Affected component
- Soup Sieve
- Fixed by upgrading
- Yes
Solution
Upgrade SoupSieve to version 2.9 or later.
Vulnerable code sample
import re
import soupsieve
from bs4 import BeautifulSoup
def select_links(html, selector):
# VULNERABLE: regex backtracking in selector parsing
soup = BeautifulSoup(html, 'html.parser')
return soup.select(selector)Patched code sample
import re
import soupsieve
from bs4 import BeautifulSoup
def select_links(html, selector):
# FIX: replace vulnerable IDENTIFIER regex with linear version
soupsieve.css_parser.IDENTIFIER = re.compile(r'[a-zA-Z_][\w-]*')
soup = BeautifulSoup(html, 'html.parser')
return soup.select(selector)Payload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202686000,
title = {{Soup Sieve regex backtracking DoS via crafted CSS selector (pre‑2.9)}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-86000},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-86000/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
