Vulnerabilities/

Denial of service in css-what

Severity:
High

Description

The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.

Recommendation

Update the css-what package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
css-what
Anything's wrong? Let us know Last updated on February 12, 2025