Improper handling of CSS at-rules in lettersanitizer
High severity
GitHub Reviewed
Published
Jun 22, 2022
in
mat-sz/lettersanitizer
•
Updated Jan 27, 2023
Description
Published to the GitHub Advisory Database
Jun 23, 2022
Reviewed
Jun 23, 2022
Published by the National Vulnerability Database
Jun 27, 2022
Last updated
Jan 27, 2023
Impact
All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule
@keyframes
.This package is depended on by react-letter, therefore everyone using react-letter is also at risk.
Patches
The problem has been patched in version 1.0.2.
Workarounds
There is no workaround besides upgrading.
References
The issue was originally reported in the react-letter repository: mat-sz/react-letter#17
For more information
If you have any questions or comments about this advisory:
References