Description
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
Recommendation
Update the css-what package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.0.0, <= 5.0.0
- Patched version(s): 5.0.1
References
Could your website be exposed too?
SmartScanner can check your website for Denial of service in css-what and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service (ReDOS) - color-string - CVE-2021-29060
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-engine - CVE-2021-21391
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-font - CVE-2021-21391
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-image - CVE-2021-21391
You might also like:
See something that needs correcting? Let us knowUpdated February 12, 2025


