Junglewise Threat Intelligence

CVE-2023-26364: Adobe css-tools regular expression denial of service in CSS parsing

CVE-2023-26364 · Severity: low · CVSS 3.1 · Published 2023-08-29

Vendors: Adobe, npm.

Executive brief

@adobe/css-tools is a JavaScript library used to parse and process CSS stylesheets. A regular expression flaw in CSS parsing allows an attacker with low privileges to submit malicious CSS that consumes excessive CPU, causing the application to become slow or unresponsive. This impacts availability of services that use the library to process untrusted CSS input.

Technical details

@adobe/css-tools versions 4.3.0 and earlier contain an inefficient regular expression (CWE-1333) in CSS parsing logic that exhibits exponential worst-case complexity. An attacker with low privileges can craft specially-crafted CSS input triggering catastrophic backtracking in the regex engine, consuming CPU resources and degrading performance. The vulnerability is reachable over the network with low attack complexity. The issue has been patched in version 4.3.1.

Affected products

  • Adobe css-tools 4.3.0 and earlier

Timeline

  • 2023-08-29: disclosed: GHSA published
  • 2023-08-29: patched: Fixed in version 4.3.1

References

Related threats