All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule @keyframes
.
This package is depended on by react-letter, therefore everyone using react-letter is also at risk.
The problem has been patched in version 1.0.2.
There is no workaround besides upgrading.
The issue was originally reported in the react-letter repository: https://github.com/mat-sz/react-letter/issues/17
If you have any questions or comments about this advisory: * Open an issue in lettersanitizer * Email me at contact@matsz.dev
{ "nvd_published_at": "2022-06-27T23:15:00Z", "severity": "HIGH", "github_reviewed_at": "2022-06-23T17:48:19Z", "github_reviewed": true, "cwe_ids": [ "CWE-754" ] }