@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
Description
Published to the GitHub Advisory Database
Aug 29, 2023
Reviewed
Aug 29, 2023
Published by the National Vulnerability Database
Nov 17, 2023
Last updated
Nov 17, 2023
Impact
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
Patches
The issue has been resolved in 4.3.1.
Workarounds
None
References
N/A
References