Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-43357

19
FAUCET Score

CVE-2022-43357 is a stack overflow vulnerability in the Sass::CompoundSelector::has_real_parent_ref function within libsass versions up to 3.6.5-8-g210218, also affecting the sassc command-line driver version 3.6.2. This flaw allows an unauthenticated attacker to remotely trigger a denial-of-service (DoS) condition with low attack complexity. The vulnerability has a CVSSv3 score of 7.5 (High), indicating a significant impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
3.6.5-8-g210218CPE matchmatch criteria
cpe:2.3:a:sass-lang:libsass:3.6.5-8-g210218:*:*:*:*:*:*:*
3.6.2CPE matchmatch criteria
cpe:2.3:a:sass-lang:sassc:3.6.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.25%
Probability of exploitation in next 30 days
EPSS Percentile
66.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0125 is in the 46th percentile among its peer group of 51,553 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

microsoftpatch availablevia msrc
Product: azl3 libsass 3.6.6-1 on Azure Linux 3.0Fixed in: 3.6.6-1
microsoftpatch availablevia msrc
Product: 18827-17084Fixed in: 3.6.6-1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2023-Aug/CVE-2022-43357Important

Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

Aug 8, 2023

References

drive.google.com / file/d/1aC5q3czen0atI91fuBIoCBFkS30_OSWX
ExploitPermissions RequiredThird Party Advisory
github.com / sass/libsass
Product
github.com / sass/libsass/issues/3177
ExploitIssue TrackingVendor Advisory