CVE-2022-26592: High severity libsass vulnerability
Published Aug 22, 2023
·Updated
Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::hasrealparentref function.
Affected Software
1 affected component
Sass-lang Libsass=3.6.5
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-26592?
CVE-2022-26592 is a stack overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.
2
How severe is CVE-2022-26592?
CVE-2022-26592 has a severity rating of 8.8 (high).
3
What software is affected by CVE-2022-26592?
The affected software is Sass-lang Libsass 3.6.5.
4
How can I fix CVE-2022-26592?
To fix CVE-2022-26592, update to a version of libsass that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-26592?
You can find more information about CVE-2022-26592 on the GitHub issue page: https://github.com/sass/libsass/issues/3174.