Vulnerable Library - entsoe_py-0.8.0-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (entsoe_py version) |
Remediation Possible** |
| CVE-2026-49477 |
High |
7.5 |
soupsieve-2.8.3-py3-none-any.whl |
Transitive |
0.8.1 |
❌ |
| CVE-2026-49476 |
High |
7.5 |
soupsieve-2.8.3-py3-none-any.whl |
Transitive |
0.8.1 |
❌ |
| CVE-2026-86000 |
Medium |
5.3 |
soupsieve-2.8.3-py3-none-any.whl |
Transitive |
N/A* |
❌ |
| CVE-2026-85999 |
Medium |
5.3 |
soupsieve-2.8.3-py3-none-any.whl |
Transitive |
N/A* |
❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-49477
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
- entsoe_py-0.8.0-py3-none-any.whl (Root Library)
- beautifulsoup4-4.14.3-py3-none-any.whl
- ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.
Publish Date: 2026-07-14
URL: CVE-2026-49477
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-836r-79rf-4m37
Release Date: 2026-07-09
Fix Resolution (soupsieve): 2.8.4
Direct dependency fix Resolution (entsoe-py): 0.8.1
Step up your Open Source Security Game with Mend here
CVE-2026-49476
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
- entsoe_py-0.8.0-py3-none-any.whl (Root Library)
- beautifulsoup4-4.14.3-py3-none-any.whl
- ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.
Publish Date: 2026-07-14
URL: CVE-2026-49476
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-2wc2-fm75-p42x
Release Date: 2026-07-09
Fix Resolution (soupsieve): 2.8.4
Direct dependency fix Resolution (entsoe-py): 0.8.1
Step up your Open Source Security Game with Mend here
CVE-2026-86000
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
- entsoe_py-0.8.0-py3-none-any.whl (Root Library)
- beautifulsoup4-4.14.3-py3-none-any.whl
- ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled selector contains a long identifier or unquoted attribute-value run followed by input that makes the overall match fail, the regular expression engine explores quadratically many splits between the overlapping groups. User-controlled selectors can reach this path through soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. The resulting CPU consumption can hold the Python GIL, exhaust application workers, and stall a service; successful plain identifier matches are linear, and the issue does not cause memory corruption or code execution. The issue is fixed in version 2.9.
Publish Date: 2026-09-17
URL: CVE-2026-86000
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Step up your Open Source Security Game with Mend here
CVE-2026-85999
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
- entsoe_py-0.8.0-py3-none-any.whl (Root Library)
- beautifulsoup4-4.14.3-py3-none-any.whl
- ❌ soupsieve-2.8.3-py3-none-any.whl (Vulnerable Library)
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9.
Publish Date: 2026-09-17
URL: CVE-2026-85999
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Step up your Open Source Security Game with Mend here
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.
Publish Date: 2026-07-14
URL: CVE-2026-49477
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-836r-79rf-4m37
Release Date: 2026-07-09
Fix Resolution (soupsieve): 2.8.4
Direct dependency fix Resolution (entsoe-py): 0.8.1
Step up your Open Source Security Game with Mend here
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.
Publish Date: 2026-07-14
URL: CVE-2026-49476
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-2wc2-fm75-p42x
Release Date: 2026-07-09
Fix Resolution (soupsieve): 2.8.4
Direct dependency fix Resolution (entsoe-py): 0.8.1
Step up your Open Source Security Game with Mend here
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacker-controlled selector contains a long identifier or unquoted attribute-value run followed by input that makes the overall match fail, the regular expression engine explores quadratically many splits between the overlapping groups. User-controlled selectors can reach this path through soupsieve.compile(), soupsieve.select(), or BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. The resulting CPU consumption can hold the Python GIL, exhaust application workers, and stall a service; successful plain identifier matches are linear, and the issue does not cause memory corruption or code execution. The issue is fixed in version 2.9.
Publish Date: 2026-09-17
URL: CVE-2026-86000
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here
Vulnerable Library - soupsieve-2.8.3-py3-none-any.whl
A modern CSS selector implementation for Beautiful Soup.
Library home page: https://files.pythonhosted.org/packages/46/2c/1462b1d0a634697ae9e55b3cecdcb64788e8b7d63f54d923fcd0bb140aed/soupsieve-2.8.3-py3-none-any.whl
Sample Path to Dependency File: /tmp/ws-ua_20260427095437_WNDCEF/cmd_PJQPMY/20260427095811/.ws-temp-BLQCAL-requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260427095437_WNDCEF/python_TIGAYB/20260427095439/soupsieve-2.8.3-py3-none-any.whl
Dependency Hierarchy:
Found in base branch: develop
Vulnerability Details
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greedy scan at every starting offset. An attacker-controlled valid selector containing a long internal whitespace run, or a selector containing a long CSS comment run followed by another token, causes quadratic CPU work before tokenization. User-controlled selectors can reach the path through soupsieve.compile() and BeautifulSoup.select(), while applications using only hard-coded selectors are unaffected. This root cause is separate from the IDENTIFIER and VALUE backtracking vulnerability because the cost occurs in RE_WS_END.search during trimming rather than token matching. The resulting CPU consumption can hold the Python GIL, exhaust workers, and stall a service without causing memory corruption or code execution. The issue is fixed in version 2.9.
Publish Date: 2026-09-17
URL: CVE-2026-85999
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here