CVE-2022-43357: Sass-Lang Libsass

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

Affected products

Published 2023-08-22. Last modified 2026-06-17.