CVE-2023-26364
published 2023-11-17CVE-2023-26364: @adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.98%
58.2th percentile
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | css-tools | < 4.3.1 | 4.3.1 |
| adobe | css-tools | >= 0 < 4.3.1 | 4.3.1 |
| adobe | not_a_product | <= 4.3.0 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
css-tools: Improper Input Validation causes Denial of Service via Regular Expression
vendor_redhat·2023-11-17·CVSS 5.3
CVE-2023-26364 [MEDIUM] CWE-20 css-tools: Improper Input Validation causes Denial of Service via Regular Expression
css-tools: Improper Input Validation causes Denial of Service via Regular Expression
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.
A flaw was found in Adobe CSS Tools. An improper input validation could result in a minor denial of service while parsing a malicious CSS with the parse component. User interaction and privileges are not required to jeopardize an environment.
Mitigation: No mitigation is yet available for this vulnerability.
Package: css-tools (Cryostat 2) - Not affected
Package: mta/mta-ui-rhel8 (Migration Toolkit for Applications 6) - Will not fix
Package: migrati
GHSA
@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
ghsa·2023-08-29
CVE-2023-26364 [MEDIUM] CWE-1333 @adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
### Impact
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
### Patches
The issue has been resolved in 4.3.1.
### Workarounds
None
### References
N/A
OSV
@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
osv·2023-08-29
CVE-2023-26364 [MEDIUM] @adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
### Impact
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.
### Patches
The issue has been resolved in 4.3.1.
### Workarounds
None
### References
N/A
No detection rules found.
No public exploits indexed.
2023-11-17
Published