Skip to content

entsoe_py-0.8.0-py3-none-any.whl: 4 vulnerabilities (highest severity is: 7.5) #1032

Description

@mend-bolt-for-github
Vulnerable Library - entsoe_py-0.8.0-py3-none-any.whl

Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (entsoe_py version) Remediation Possible**
CVE-2026-49477 High 7.5 soupsieve-2.8.3-py3-none-any.whl Transitive 0.8.1 ❌
CVE-2026-49476 High 7.5 soupsieve-2.8.3-py3-none-any.whl Transitive 0.8.1 ❌
CVE-2026-86000 Medium 5.3 soupsieve-2.8.3-py3-none-any.whl Transitive N/A* ❌
CVE-2026-85999 Medium 5.3 soupsieve-2.8.3-py3-none-any.whl Transitive N/A* ❌

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-49477

Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl

A modern CSS selector implementation for Beautiful Soup.

Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl

Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl

Dependency Hierarchy:

  • entsoe_py-0.8.0-py3-none-any.whl (Root Library)
    • beautifulsoup4-4.14.3-py3-none-any.whl
      • ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.

Publish Date: 2026-07-14

URL: CVE-2026-49477

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-836r-79rf-4m37

Release Date: 2026-07-09

Fix Resolution (soupsieve): 2.8.4

Direct dependency fix Resolution (entsoe-py): 0.8.1

Step up your Open Source Security Game with Mend here

CVE-2026-49476

Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl

A modern CSS selector implementation for Beautiful Soup.

Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl

Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl

Dependency Hierarchy:

  • entsoe_py-0.8.0-py3-none-any.whl (Root Library)
    • beautifulsoup4-4.14.3-py3-none-any.whl
      • ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.

Publish Date: 2026-07-14

URL: CVE-2026-49476

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-2wc2-fm75-p42x

Release Date: 2026-07-09

Fix Resolution (soupsieve): 2.8.4

Direct dependency fix Resolution (entsoe-py): 0.8.1

Step up your Open Source Security Game with Mend here

CVE-2026-86000

Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl

A modern CSS selector implementation for Beautiful Soup.

Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl

Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl

Dependency Hierarchy:

  • entsoe_py-0.8.0-py3-none-any.whl (Root Library)
    • beautifulsoup4-4.14.3-py3-none-any.whl
      • ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled selector contains a long identifier or unquoted attribute-value run followed by input that makes the overall match fail, the regular expression engine explores quadratically many splits between the overlapping groups. User-controlled selectors can reach this path through soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. The resulting CPU consumption can hold the Python GIL, exhaust application workers, and stall a service; successful plain identifier matches are linear, and the issue does not cause memory corruption or code execution. The issue is fixed in version 2.9.

Publish Date: 2026-09-17

URL: CVE-2026-86000

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

CVE-2026-85999

Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl

A modern CSS selector implementation for Beautiful Soup.

Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl

Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl

Dependency Hierarchy:

  • entsoe_py-0.8.0-py3-none-any.whl (Root Library)
    • beautifulsoup4-4.14.3-py3-none-any.whl
      • ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9.

Publish Date: 2026-09-17

URL: CVE-2026-85999

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions