Executive brief
@adobe/css-tools is a JavaScript library used to parse and process CSS stylesheets. A regular expression flaw in CSS parsing allows an attacker with low privileges to submit malicious CSS that consumes excessive CPU, causing the application to become slow or unresponsive. This impacts availability of services that use the library to process untrusted CSS input.
Technical details
@adobe/css-tools versions 4.3.0 and earlier contain an inefficient regular expression (CWE-1333) in CSS parsing logic that exhibits exponential worst-case complexity. An attacker with low privileges can craft specially-crafted CSS input triggering catastrophic backtracking in the regex engine, consuming CPU resources and degrading performance. The vulnerability is reachable over the network with low attack complexity. The issue has been patched in version 4.3.1.
Affected products
- Adobe css-tools 4.3.0 and earlier
Timeline
- 2023-08-29: disclosed: GHSA published
- 2023-08-29: patched: Fixed in version 4.3.1