CVE-2018-11499 is a critical use-after-free vulnerability in LibSass versions 3.4.x and 3.5.x through 3.5.4, specifically within the handle_error() function in sass_context.cpp. This flaw carries a CVSS score of 9.8 (Critical) due to its network-exploitable nature, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While the vulnerability could lead to a denial of service (application crash), other unspecified impacts are also possible. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.4.0, <= 3.5.4CPE matchmatch criteria | cpe:2.3:a:sass-lang:libsass:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.