---
id: CVE-2026-49477
title: >-
  soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings
  (CVE-2026-49477)
summary: >-
  A flaw was found in soupsieve, a CSS selector library. This vulnerability
  allows a remote attacker to cause a Denial of Service (DoS) by supplying
  specially crafted, untrusted CSS selector strings. The flaw occurs due to a
  regular expressi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-1333
  - CWE-400
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - lightspeed_core
  - migration_toolkit_for_applications 8
  - ansible_automation_platform 2
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_virtualization 4
  - hardened_images
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.9
patched:
  - hardened_images
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.9
published: '2026-07-14'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:04:24+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49477.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49477.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-49477'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2500752'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-49477'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49477'
  - url: >-
      https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3
  - url: 'https://github.com/facelessuser/soupsieve/releases/tag/2.8.4'
  - url: >-
      https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37
  - url: 'https://access.redhat.com/errata/RHSA-2026:34119'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66084'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66523'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70267'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63307'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69255'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65514'
  - url: 'https://github.com/advisories/GHSA-836r-79rf-4m37'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - pip
epss: 0.00522
epssPercentile: 0.43294
aliases:
  - GHSA-836r-79rf-4m37
ecosystem: pip
ingestedAt: '2026-07-09T13:51:05.192Z'
---

## Overview

A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value, leading to CPU exhaustion.

## Vendor advisories

- **RHSA-2026:34119** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34119)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:66084** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66084)
- **RHSA-2026:66523** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66523)
- **RHSA-2026:70267** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70267)
- **RHSA-2026:63307** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63307)
- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)
- **RHSA-2026:65514** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65514)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Ansible Automation Platform 2, Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49477.json)

**soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-22.

Affected:

- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Applications 8
- Red Hat Ansible Automation Platform 2
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4

Fixed:

- Red Hat Hardened Images
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

No fix planned:

- Red Hat Ansible Automation Platform 2
- Exploit Intelligence
- Lightspeed Core
- Migration Toolkit for Applications 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4

Not affected:

- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat Hardened Images

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:34119
For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:66084

## Package advisory (CVE-2026-49477)

Affected packages:

- `soupsieve <= 2.8.3`

Patched in:

- `soupsieve 2.8.4`

Source: https://github.com/advisories/GHSA-836r-79rf-4m37
