VDB
Sign up
MEDIUM5.0

GHSA-hpx4-r86g-5jrg

@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS

Quick fix

GHSA-hpx4-r86g-5jrg — @adobe/css-tools: upgrade to the fixed version with the command below.

npm install @adobe/css-tools@4.3.1

Details

### Impact @adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

### Patches The issue has been resolved in 4.3.1.

### Workarounds None

### References N/A

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@adobe/css-tools
Introduced in: 0Fixed in: 4.3.1
Fixnpm install @adobe/css-tools@4.3.1

References