CVE-2018-19826: Medium severity libsass vulnerability
DISPUTED In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator()(Sass::StringQuoted) stack frame) may cause a Denial of Service via crafted sass input files with stray '&' or '/' characters. NOTE: Upstream comments indicate this issue is closed as "won't fix" and "works as intended" by design.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19826?
CVE-2018-19826 is a vulnerability in LibSass 3.5.5 that can cause a Denial of Service via crafted sass input files with stray '&' or '/' characters.
What is the severity of CVE-2018-19826?
The severity of CVE-2018-19826 is medium (6.5).
How does CVE-2018-19826 affect LibSass?
CVE-2018-19826 affects LibSass 3.5.5.
How can I fix the CVE-2018-19826 vulnerability?
To fix the CVE-2018-19826 vulnerability, update to a version of LibSass that is not affected by this issue.
Is there any additional information about CVE-2018-19826?
For more information about CVE-2018-19826, refer to the GitHub issue linked in the references.