Moderate severityNVD Advisory· Published Nov 17, 2023· Updated Aug 29, 2024
Denial of Service of regular expression in package @adobe/css-tools
CVE-2023-26364
Description
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@adobe/css-toolsnpm | < 4.3.1 | 4.3.1 |
Affected products
4- ghsa-coords3 versionspkg:npm/%40adobe/css-toolspkg:rpm/suse/cockpit-wicked&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/cockpit-wicked&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
< 4.3.1+ 2 more
- (no CPE)range: < 4.3.1
- (no CPE)range: < 4.5-150400.3.3.1
- (no CPE)range: < 5~git8.c06c55b-150500.3.3.1
- Adobe/Not a productv5Range: 0
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
4News mentions
0No linked articles in our index yet.