Skip to content

Regular Expression Denial of Service (ReDOS) while Parsing CSS

Moderate
holblin published GHSA-hpx4-r86g-5jrg Aug 29, 2023

Package

npm @adobe/css-tools (npm)

Affected versions

<4.3.1

Patched versions

4.3.1

Description

Impact

@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

Patches

The issue has been resolved in 4.3.1.

Workarounds

None

References

N/A

Severity

Moderate
5.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

CVE ID

CVE-2023-26364