Skip to main content

Vendor/product archive

scss-tokenizer_project / scss-tokenizer CVEs

Beta · best-effort

1 CVEs tagged to scss-tokenizer_project / scss-tokenizer0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-25758

Published Jul 1, 2022

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1