Description
All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.
Remediation
References
https://github.com/sasstools/scss-tokenizer/issues/45
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2936782
https://snyk.io/vuln/SNYK-JS-SCSSTOKENIZER-2339884
Related Vulnerabilities
CVE-2022-28355 Vulnerability in maven package org.scala-js:scalajs-library_2.11
CVE-2021-39153 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-41183 Vulnerability in npm package jquery-ui
CVE-2019-10744 Vulnerability in maven package org.webjars.bower:lodash
CVE-2020-27428 Vulnerability in npm package scratch-svg-renderer