PT-2021-4281 · Css-What+3 · Css-What+3

Published

2021-05-28

·

Updated

2025-11-18

·

CVE-2021-33587

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions css-what versions 4.0.0 through 5.0.0
Description The issue is related to an error in input size validation in the css-what package, which can lead to a denial of service. This can be exploited by a remote attacker. The problem arises because the package does not ensure that attribute parsing has linear time complexity relative to the size of the input.
Recommendations For versions 4.0.0 through 5.0.0, consider restricting the size of input data to prevent exploitation until a patch is available. As a temporary workaround, consider implementing additional validation checks on input data to minimize the risk of denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04889
CVE-2021-33587
DLA-3350-1
GHSA-Q8PJ-2VQX-8GGC
USN-6065-1

Affected Products

Bitbucket
Linuxmint
Ubuntu
Css-What