Vulnerabilities/

Regular Expression Denial of Service in clean-css

Severity:
Low

Description

Version of clean-css prior to 4.1.11 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.

Recommendation

Update the clean-css package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
clean-css
Anything's wrong? Let us know Last updated on April 11, 2023

This issue is available in SmartScanner Professional

See Pricing