CVE-2021-33587

HIGH

css-what 4.0.0-5.0.0 - Denial of Service via Attribute Parsing

Title source: llm
STIX 2.1

Description

The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (4)
css-what_project/css-what 4.0.0
css-what_project/css-what 5.0.0
netapp/e-series_performance_analyzer
npm/css-what 4.0.0 - 5.0.1npm
Published May 28, 2021
Tracked Since Feb 18, 2026