In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:w3c:css_validator:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "2020-01-19"
}
],
"source": "CPE_RANGE",
"vendor_product": "w3c:css_validator"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-4070.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "327506727195512130857608281471890945436",
"length": 1498
},
"id": "CVE-2020-4070-27bf7adc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"target": {
"file": "org/w3c/css/css/StyleSheetParser.java",
"function": "parseURL"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"287126531491259831142828594517899965709",
"166151882237851564633381564464035597352",
"217623342706874349683039718344875380745",
"25486391784260251365600363288280579394"
],
"threshold": 0.9
},
"id": "CVE-2020-4070-dd4b0a2a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"target": {
"file": "org/w3c/css/css/StyleSheetParser.java"
}
}
]
"2026-07-09T01:25:34Z"