Regular Expression Denial of Service in clean-css
Low severity
GitHub Reviewed
Published
Jun 5, 2019
to the GitHub Advisory Database
•
Updated Apr 11, 2023
Description
Reviewed
Jun 5, 2019
Published to the GitHub Advisory Database
Jun 5, 2019
Last updated
Apr 11, 2023
Version of
clean-css
prior to 4.1.11 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.Recommendation
Upgrade to version 4.1.11 or higher.
References