logo

Database

Asymmetric denial of service In css-what

Description

css-what vulnerable to ReDoS due to use of insecure regular expression The package css-what before 2.1.3 is vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-HRSSK – Vulnerability | Fluid Attacks Database