soupsieve
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting soupsievepage 1 of 1
- CVE-2026-49476HIGHCVSS 7.5EG 7.5✓ Fixed in 2.8.42026-07-09
vulnerable: 0.4 ... 2.8.3 (51 versions)
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who c…
- CVE-2026-49477HIGHCVSS 7.5EG 7.5✓ Fixed in 2.8.42026-07-09
vulnerable: 0.4 ... 2.8.3 (51 versions)
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selecto…
Check whether soupsieve is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for soupsieve CVEs against the assets you own.
Start Free Scan →