6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether soupsieve is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-86000
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
MEDIUM 5.3
CVE-2026-85999
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
HIGH 7.5
CVE-2026-49477
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
HIGH 7.5
CVE-2026-49476
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
HIGH 7.5
CVE-2026-49477
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
HIGH 7.5
CVE-2026-49476
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes