Skip to content

Improper handling of CSS at-rules in lettersanitizer

High
mat-sz published GHSA-7r3r-gq8p-v9jj Jun 22, 2022

Package

npm lettersanitizer (npm)

Affected versions

< 1.0.2

Patched versions

1.0.2

Description

Impact

All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes.

This package is depended on by react-letter, therefore everyone using react-letter is also at risk.

Patches

The problem has been patched in version 1.0.2.

Workarounds

There is no workaround besides upgrading.

References

The issue was originally reported in the react-letter repository: mat-sz/react-letter#17

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-31103