Impact
CSSOM through 0.5.0 contains a flaw in the CSSStyleDeclaration.setProperty() method that does not check for reserved property names. A stylesheet that declares a property named length can overwrite the internal counter used during cssText serialization, causing the library to allocate an excessive amount of memory. When the serialization routine is executed the process consuming the stylesheet crashes, resulting in a denial of service for the user or any other process that parses the malicious CSS.
Affected Systems
The vulnerability exists in every release of CSSOM up to and including version 0.5.0. Any application, framework, or browser engine that embeds this version of CSSOM for parsing or rendering stylesheets is potentially affected, regardless of the language or runtime that hosts it.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity impact, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker providing a malicious stylesheet—such as through a web page, an email client, or a browser extension—to a system that uses CSSOM. Successful exploitation would cause the style parsing process to abort, resulting in a local denial of service for the affected user or application.
OpenCVE Enrichment