CVE-2022-25758

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
References
Configurations

Configuration 1

cpe:2.3:a:scss-tokenizer_project:scss-tokenizer:*:*:*:*:*:node.js:*:*

Information

Published : 2022-07-01 08:15

Updated : 2022-07-12 06:53


NVD link : CVE-2022-25758

Mitre link : CVE-2022-25758

Products Affected
No products.