Description
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
Remediation
References
https://github.com/fb55/css-what/releases/tag/v5.0.1
https://lists.debian.org/debian-lts-announce/2023/03/msg00001.html
https://security.netapp.com/advisory/ntap-20210706-0007/
Related Vulnerabilities
CVE-2021-24033 Vulnerability in npm package react-dev-utils
CVE-2014-0086 Vulnerability in maven package org.richfaces.core:richfaces-core-impl
CVE-2021-21423 Vulnerability in npm package projen
CVE-2017-9805 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-10758 Vulnerability in maven package org.keycloak:keycloak-wildfly-server-subsystem