CVE-2023-26364: Adobe Css-Tools

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.

Affected products

  • Adobe Css-Tools: before 4.3.1 (fixed in 4.3.1)

Published 2023-11-17. Last modified 2026-06-17.