Skip to main content
EPSS 0.6%top 51%

Papis: Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists (CVE-2026-49476)

0
High
Published: 08/13/2026 (08/13/2026, 17:25:32 UTC)
Source: GCVE Database
Product: papis

Description

### Summary The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()` can cause the application to allocate hundreds of megabytes of heap memory from a relatively small input, leading to memory exhaustion and denial of service. To be completely transparent, AI tools helped surface this issue. However, it was independently reproduced and carefully validated. Researchers follow responsible disclosure practices and originally shared this report privately. A **500 KB** selector string triggers allocation of approximately **244 MB** of heap memory - a 488x— amplification ratio**. ### Details **Affected code:** `soupsieve/css_parser.py`, lines ~204, 925, 1106 The soupsieve CSS parser splits comma-separated selector lists and creates one `CSSSelector` object per list item. Each `CSSSelector` object contains parsed selector data structures including `SelectorList`, `Selector`, and associated tag/attribute/pseudo-class metadata. When a selector string such as `a,a,a,...` (with 250,000 comma-separated items) is passed to `sv.compile()`, the parser: 1. Tokenises the entire string and identifies each comma-delimited segment (line ~1106) 2. Parses each segment into a full `Selector` object with all associated metadata (line ~925) 3. Stores all parsed selectors in a `SelectorList` (line ~204) **Root cause:** No limit is enforced on the number of selectors in a comma-separated list. The parser will attempt to parse and store an arbitrary number of selectors, with each selector object consuming approximately **976 bytes** of heap memory. The total allocation scales linearly with the number of list items, but the amplification ratio (output memory / input bytes) is extremely high because each single-character selector like `a` expands into a complex object graph. **Attack surface:** Any application that passes user-supplied CSS selectors to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.select_one()`. ### Proof of Concept ```python import tracemalloc import soupsieve as sv tracemalloc.start() # Build a 500 KB selector string: "a,a,a,...,a" (250,000 items) count = 250_000 selector = ",".join("a" for _ in range(count)) print(f"Selector string size: {len(selector):,} bytes ({len(selector) / 1024:.0f} KB)") # Compile the selector — this allocates ~244 MB compiled = sv.compile(selector) current, peak = tracemalloc.get_traced_memory() tracemalloc.stop() print(f"Compiled selector count: {len(compiled.selectors):,}") print(f"Current memory: {current / 1024 / 1024:.1f} MB") print(f"Peak memory: {peak / 1024 / 1024:.1f} MB") print(f"Amplification ratio: {peak / len(selector):.0f}x") # Expected output: # Selector string size: 499,999 bytes (488 KB) # Compiled selector count: 250,000 # Current memory: ~244 MB # Peak memory: ~244 MB # Amplification ratio: ~488x ``` ### Impact **Severity: High** An attacker can exhaust available memory on any server-side Python application that compiles user-supplied CSS selectors via soupsieve. This can cause: - **OOM kills** in containerised deployments (Kubernetes pods, Docker containers) with memory limits - **Swap thrashing** on bare-metal servers, degrading performance for all co-located processes - **Process termination** via Python's `MemoryError` exception if the system runs out of addressable memory | Parameter | Value | |---|---| | Input size | ~500 KB selector string | | Memory allocated | ~244 MB | | Amplification ratio | ~488× | | Per-object overhead | ~976 bytes per selector | | Authentication required | None | | User interaction required | None | **Scalability of attack:** The memory allocation scales linearly - doubling the selector count doubles memory usage. An attacker can tune the payload to exactly exhaust a target's memory limits. Multiple concurrent requests multiply the effect. **Downstream exposure:** soupsieve is an automatic dependency of `beautifulsoup4`, one of the most widely installed Python packages. Any web application accepting CSS selectors from users (e.g., web scraping APIs, content filtering tools, CMS preview features) is potentially affected. --- ### Credit Discovered by a security research team from the University of Sydney, focused on detecting open source software vulnerabilities. Liyi Zhou: https://lzhou1110.github.io/ Ziyue Wang: https://zyy0530.github.io/ Strick: https://str1ckl4nd.github.io/ Maurice: https://maurice.busystar.org/ Chenchen Yu: https://7thparkk.github.io/

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

PyPIghsa
soupsieve
Affected versions
<2.8.4
Homebrewmore threats →ghsa
adr-viewer
pkg:brew/adr-viewer
Affected versions
>=1.3.0 <1.4.0_6
Homebrewmore threats →ghsa
toot
pkg:brew/toot
Affected versions
>=0.26.0 <0.52.1_2
Homebrewmore threats →ghsa
checkov
pkg:brew/checkov
Affected versions
>=1.0.855 <3.2.530
Homebrewmore threats →ghsa
jupyterlab
pkg:brew/jupyterlab
Affected versions
>=3.3.2 <4.5.8
Homebrewmore threats →ghsa
papis
pkg:brew/papis
Affected versions
>=0.14.1 <0.15.0_5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 23:07:32 UTC

Technical Analysis

The Red Hat security advisory RHSA-2026:23992 reports a high-severity vulnerability affecting Red Hat Hardened Images RPMs, particularly the python-attrs package versions python3-attrs-26.1.0-3.hum1 (noarch) and python-attrs-26.1.0-3.hum1.src (src). The vulnerabilities correspond to CVE-2026-49476 and CVE-2026-49477 and relate to resource management issues (CWE-770) and potentially improper handling of system resources (CWE-1333). The CVSS vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to availability (denial of service). The advisory does not explicitly state that a patch is available or provide remediation instructions beyond referencing the update. No known exploits have been reported in the wild.

Potential Impact

The vulnerabilities can cause a denial of service condition affecting the availability of systems using the affected Red Hat Hardened Images RPMs, specifically the python-attrs package. There is no indication of confidentiality or integrity impact. No known exploits have been reported, suggesting limited or no active exploitation at this time.

Mitigation Recommendations

The Red Hat advisory references an update including the python-attrs RPMs (python3-attrs-26.1.0-3.hum1 noarch and python-attrs-26.1.0-3.hum1 src) but does not explicitly confirm that these updates fully remediate the vulnerabilities. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/errata/RHSA-2026:23992 and https://images.redhat.com/ for current remediation guidance and instructions on applying updates. No additional mitigation steps are provided by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-2wc2-fm75-p42x
Osv Schema Version
1.4.0
Aliases
["CVE-2026-49476"]
Ecosystems
["PyPI"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a4fa9a168715ace437d3dd0

Added to database: 07/09/2026, 14:01:05 UTC

Last enriched: 07/30/2026, 23:07:32 UTC

Last updated: 10/08/2026, 18:48:46 UTC

Views: 193

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses