Description
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471786
Related Vulnerabilities
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-common
CVE-2020-28503 Vulnerability in npm package copy-props
CVE-2022-48216 Vulnerability in npm package @uniswap/universal-router
CVE-2022-37223 Vulnerability in maven package com.jflyfox:jflyfox_jfinal