Description
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
Remediation
References
https://github.com/fb55/css-what/releases/tag/v5.0.1
https://lists.debian.org/debian-lts-announce/2023/03/msg00001.html
https://security.netapp.com/advisory/ntap-20210706-0007/
Related Vulnerabilities
CVE-2017-14063 Vulnerability in maven package org.asynchttpclient:async-http-client-project
CVE-2017-5656 Vulnerability in maven package org.apache.cxf:cxf-rt-ws-security
CVE-2020-6449 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-5388 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2023-25761 Vulnerability in maven package org.jenkins-ci.plugins:junit