Junglewise Threat Intelligence

CVE-2022-21222: css-what regular expression denial of service

CVE-2022-21222 · Severity: low · CVSS 3.1 · Published 2022-10-01

Vendors: npm.

Executive brief

css-what is a JavaScript library used to parse CSS selectors. A flaw in its regular expression logic allows attackers to craft malicious input that causes the parser to consume excessive CPU resources, resulting in denial of service. Applications that use this library to process untrusted CSS selectors could become unresponsive.

Technical details

css-what before version 2.1.3 contains a Regular Expression Denial of Service (ReDoS) vulnerability in the re_attr variable within index.js. The insecure regular expression can be triggered via the parse() function when processing specially crafted CSS selector strings. An attacker can send a malicious selector string over the network to any application using the vulnerable library, causing exponential backtracking in the regex engine and effectively freezing the application. No authentication or user interaction is required. The vulnerability was patched in version 2.1.3.

Affected products

  • css-what css-what before 2.1.3

Timeline

  • 2022-10-01: disclosed
  • 2022-10-01: patched: Version 2.1.3 released

References

Related threats