HIGH7.5
GHSA-q8pj-2vqx-8ggc
Denial of service in css-what
Quick fix
GHSA-q8pj-2vqx-8ggc — css-what: upgrade to the fixed version with the command below.
npm install css-what@5.0.1Details
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-33587[ADVISORY]
- https://github.com/fb55/css-what/commit/4cdaacfd0d4b6fd00614be030da0dea6c2994655[WEB]
- https://github.com/fb55/css-what[PACKAGE]
- https://github.com/fb55/css-what/releases/tag/v5.0.1[WEB]
- https://lists.debian.org/debian-lts-announce/2023/03/msg00001.html[WEB]
- https://security.netapp.com/advisory/ntap-20210706-0007[WEB]