Description
There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, leading to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1482331
Related Vulnerabilities
CVE-2020-5207 Vulnerability in maven package io.ktor:ktor-server-cio
CVE-2021-21316 Vulnerability in npm package less-openui5
CVE-2016-0750 Vulnerability in maven package org.infinispan:infinispan-client-hotrod
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-manager
CVE-2019-7722 Vulnerability in maven package net.sourceforge.pmd:pmd-core