Source: sass-grass Version: 0.13.4-6 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for sass-grass. CVE-2026-14650[0]: | A flaw has been found in connorskees grass up to 0.13.4. The | affected element is the function grass_compiler::raw_to_parse_error | of the component UTF-8 Character Handler. Executing a manipulation | can lead to denial of service. The attack is restricted to local | execution. The exploit has been published and may be used. In Issue | #117 with similar structure the project maintainer explains: "DoS | vulnerabilities are generally fine in Sass compilers -- they are | trivially possible with recursive functions, infinite loops, nested | mixins, etc. The description here is wrong. Compile time is not | expected to be linear relative to the input, and the @extend | algorithm is definitionally exponential." CVE-2026-14651[1]: | A vulnerability has been found in connorskees grass up to 0.13.4. | The impacted element is the function | grass_compiler::selector::extend/grass_compiler::evaluate::visitor. | The manipulation leads to denial of service. The attack must be | carried out locally. The exploit has been disclosed to the public | and may be used. The project maintainer explains: "DoS | vulnerabilities are generally fine in Sass compilers -- they are | trivially possible with recursive functions, infinite loops, nested | mixins, etc. The description here is wrong. Compile time is not | expected to be linear relative to the input, and the @extend | algorithm is definitionally exponential." If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-14650 https://www.cve.org/CVERecord?id=CVE-2026-14650 [1] https://security-tracker.debian.org/tracker/CVE-2026-14651 https://www.cve.org/CVERecord?id=CVE-2026-14651 Regards, Salvatore

