Description
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6284 | All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex. |
Github GHSA |
GHSA-7mwh-4pqv-wmr8 | Regular expression denial of service in scss-tokenizer |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-17T01:06:29.282Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25758
No data.
Status : Modified
Published: 2022-07-01T20:15:07.847
Modified: 2024-11-21T06:52:56.980
Link: CVE-2022-25758
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA