Executive brief
css-what is a JavaScript library used to parse CSS selectors. A flaw in its regular expression logic allows attackers to craft malicious input that causes the parser to consume excessive CPU resources, resulting in denial of service. Applications that use this library to process untrusted CSS selectors could become unresponsive.
Technical details
css-what before version 2.1.3 contains a Regular Expression Denial of Service (ReDoS) vulnerability in the re_attr variable within index.js. The insecure regular expression can be triggered via the parse() function when processing specially crafted CSS selector strings. An attacker can send a malicious selector string over the network to any application using the vulnerable library, causing exponential backtracking in the regex engine and effectively freezing the application. No authentication or user interaction is required. The vulnerability was patched in version 2.1.3.
Affected products
- css-what css-what before 2.1.3
Timeline
- 2022-10-01: disclosed
- 2022-10-01: patched: Version 2.1.3 released