GHSA-wxhq-pm8v-cw75
ADVISORY - githubSummary
Version of clean-css prior to 4.1.11 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.
Recommendation
Upgrade to version 4.1.11 or higher.
Common Weakness Enumeration (CWE)
ADVISORY - github
Inefficient Regular Expression Complexity
ADVISORY - gitlab
ADVISORY - gitlab
ADVISORY - gitlab
ADVISORY - gitlab
ADVISORY - gitlab
ADVISORY - gitlab
ADVISORY - gitlab
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-wxhq-pm8v-cw75
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
N/Alow| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| clean-css | npm | - | - | <4.1.11 | 4.1.11 |
Severity and metrics
No CVSS data available from this advisory.