Description
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471786
Related Vulnerabilities
CVE-2020-26237 Vulnerability in npm package highlight.js
CVE-2020-13954 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http
CVE-2020-7747 Vulnerability in npm package lightning-server
CVE-2019-1010266 Vulnerability in npm package lodash
CVE-2021-21122 Vulnerability in maven package org.webjars.npm:electron