First published: Tue Aug 29 2023(Updated: )
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/@adobe/css-tools | <4.3.1 | 4.3.1 |
redhat/css-tools | <4.3.1 | 4.3.1 |
Adobe CSS Tools | <4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26364 has a severity rating that suggests it can lead to a minor denial of service.
To fix CVE-2023-26364, upgrade @adobe/css-tools to version 4.3.1 or later.
Versions of @adobe/css-tools up to and including 4.3.0 are affected by CVE-2023-26364.
No, exploitation of CVE-2023-26364 does not require user interaction.
Yes, CVE-2023-26364 can be exploited without any special privileges.