Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
cvss
0.0
low
severity band, no base score published
epss
not scored
chance of exploitation in 30 days
xyz score
0.0
low
CyberXYZ composite out of 10
fig. 01 — GHSA-wxhq-pm8v-cw75, the advisory selected below
// 1 advisories
GHSA-wxhq-pm8v-cw75
LOW
Version of clean-css prior to 4.1.11 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.
// recommendation
Upgrade to version 4.1.11 or higher.
Checked 2026-10-04 at 01:08 UTC. The most recent advisory here was published 2019-06-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.