In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:w3c:css_validator:*:*:*:*:*:*:*:*"
],
"vendor_product": "w3c:css_validator",
"extracted_events": [
{
"last_affected": "2020-01-19"
}
]
}
]
}[
{
"digest": {
"length": 1498.0,
"function_hash": "327506727195512130857608281471890945436"
},
"signature_version": "v1",
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"signature_type": "Function",
"target": {
"function": "parseURL",
"file": "org/w3c/css/css/StyleSheetParser.java"
},
"id": "CVE-2020-4070-27bf7adc",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"287126531491259831142828594517899965709",
"166151882237851564633381564464035597352",
"217623342706874349683039718344875380745",
"25486391784260251365600363288280579394"
]
},
"signature_version": "v1",
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"signature_type": "Line",
"target": {
"file": "org/w3c/css/css/StyleSheetParser.java"
},
"id": "CVE-2020-4070-dd4b0a2a",
"deprecated": false
}
]
"2026-07-09T01:25:34Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-4070.json"