CVE-2018-19837 describes a denial-of-service vulnerability in LibSass versions prior to 3.5.5, affecting the sass-lang libsass product. This flaw, rated Medium severity with a CVSS score of 6.5, allows remote attackers to cause stack consumption and crash the application by providing a specially crafted Sass file that incorrectly parses the '%' character as a modulo operator. While the attack complexity is low, user interaction is required. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.5CPE matchmatch criteria | cpe:2.3:a:sass-lang:libsass:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.