CVE-2018-11499: Sass-Lang Libsass
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.
Affected products
- Sass-Lang Libsass: from 3.4.0, up to and including 3.5.4
Published 2018-05-26. Last modified 2026-06-17.