CVE-2026-93752
EUVD-2026-8325718.09.2026, 18:18
CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter and trigger excessive memory allocation during cssText serialization, causing process termination.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References