{"id":"CVE-2026-49477","title":"soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings (CVE-2026-49477)","summary":"A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expressi…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-1333","CWE-400"],"vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["exploit_intelligence","lightspeed_core","migration_toolkit_for_applications 8","ansible_automation_platform 2","openshift_ai_rhoai","openshift_container_platform 4","openshift_virtualization 4","hardened_images","openshift_ai 3.4","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9"],"patched":["hardened_images","openshift_ai 3.4","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9"],"published":"2026-07-14","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:33:03+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49477.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49477.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-49477"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500752"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49477"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49477"},{"url":"https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3"},{"url":"https://github.com/facelessuser/soupsieve/releases/tag/2.8.4"},{"url":"https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37"},{"url":"https://access.redhat.com/errata/RHSA-2026:34119"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:66084"},{"url":"https://access.redhat.com/errata/RHSA-2026:66523"},{"url":"https://access.redhat.com/errata/RHSA-2026:63307"},{"url":"https://access.redhat.com/errata/RHSA-2026:69255"},{"url":"https://access.redhat.com/errata/RHSA-2026:65514"},{"url":"https://github.com/advisories/GHSA-836r-79rf-4m37"}],"tags":["csaf","vex","red-hat","ghsa","pip"],"epss":0.00522,"epssPercentile":0.431,"aliases":["GHSA-836r-79rf-4m37"],"ecosystem":"pip","ingestedAt":"2026-07-09T13:51:05.192Z","slug":"CVE-2026-49477","body":"## Overview\n\nA flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value, leading to CPU exhaustion.\n\n## Vendor advisories\n\n- **RHSA-2026:34119** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34119)\n- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)\n- **RHSA-2026:66084** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66084)\n- **RHSA-2026:66523** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66523)\n- **RHSA-2026:63307** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63307)\n- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)\n- **RHSA-2026:65514** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65514)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Ansible Automation Platform 2, Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49477.json)\n\n**soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-21.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- Migration Toolkit for Applications 8\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n\nFixed:\n\n- Red Hat Hardened Images\n- Red Hat OpenShift AI 3.4\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n\nNo fix planned:\n\n- Red Hat Ansible Automation Platform 2\n- Exploit Intelligence\n- Lightspeed Core\n- Migration Toolkit for Applications 8\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n\nNot affected:\n\n- Red Hat OpenShift AI 3.4\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:34119\nFor Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:66084\n\n## Package advisory (CVE-2026-49477)\n\nAffected packages:\n\n- `soupsieve <= 2.8.3`\n\nPatched in:\n\n- `soupsieve 2.8.4`\n\nSource: https://github.com/advisories/GHSA-836r-79rf-4m37","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}