Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1ocHg0LXI4NmctNWpyZ84AA1jW
@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
Impact
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
Patches
The issue has been resolved in 4.3.1.
Workarounds
None
References
N/A
Permalink: https://github.com/advisories/GHSA-hpx4-r86g-5jrgJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ocHg0LXI4NmctNWpyZ84AA1jW
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 year ago
Updated: 10 months ago
CVSS Score: 5.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Identifiers: GHSA-hpx4-r86g-5jrg, CVE-2023-26364
References:
- https://github.com/adobe/css-tools/security/advisories/GHSA-hpx4-r86g-5jrg
- https://github.com/adobe/css-tools/commit/2b09a25d1dbdbb16fe80065e4c9beb5623ee5793
- https://nvd.nist.gov/vuln/detail/CVE-2023-26364
- https://github.com/advisories/GHSA-hpx4-r86g-5jrg
Blast Radius: 27.7
Affected Packages
npm:@adobe/css-tools
Dependent packages: 35Dependent repositories: 350,800
Downloads: 40,683,622 last month
Affected Version Ranges: < 4.3.1
Fixed in: 4.3.1
All affected versions: 4.0.0, 4.0.1, 4.0.2, 4.1.0, 4.2.0, 4.3.0
All unaffected versions: 4.3.1, 4.3.2, 4.3.3, 4.4.0