Source: sass-grass
Version: 0.13.4-6
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for sass-grass.

CVE-2026-14650[0]:
| A flaw has been found in connorskees grass up to 0.13.4. The
| affected element is the function grass_compiler::raw_to_parse_error
| of the component UTF-8 Character Handler. Executing a manipulation
| can lead to denial of service. The attack is restricted to local
| execution. The exploit has been published and may be used. In Issue
| #117 with similar structure the project maintainer explains: "DoS
| vulnerabilities are generally fine in Sass compilers -- they are
| trivially possible with recursive functions, infinite loops, nested
| mixins, etc. The description here is wrong. Compile time is not
| expected to be linear relative to the input, and the @extend
| algorithm is definitionally exponential."


CVE-2026-14651[1]:
| A vulnerability has been found in connorskees grass up to 0.13.4.
| The impacted element is the function
| grass_compiler::selector::extend/grass_compiler::evaluate::visitor.
| The manipulation leads to denial of service. The attack must be
| carried out locally. The exploit has been disclosed to the public
| and may be used. The project maintainer explains: "DoS
| vulnerabilities are generally fine in Sass compilers -- they are
| trivially possible with recursive functions, infinite loops, nested
| mixins, etc. The description here is wrong. Compile time is not
| expected to be linear relative to the input, and the @extend
| algorithm is definitionally exponential."


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14650
    https://www.cve.org/CVERecord?id=CVE-2026-14650
[1] https://security-tracker.debian.org/tracker/CVE-2026-14651
    https://www.cve.org/CVERecord?id=CVE-2026-14651

Regards,
Salvatore

Reply via email to