GHSA-9pmc-p236-855h
HIGHCVE-2026-53727CssParser::Parser#readremotefile (and therefore loaduri!, and the @import-following branch of addblock!) issues HTTP/HTTPS requests against any host, port and URI it is handed, with no scheme allowlist, no host / IP filtering, and no protection against link-local, loopback or RFC‑1918 addresses. Location: redirects are followed recursively back into the same function, which also services file:// U
- Affected
- < 3.0.0
- Fixed in
- 3.0.0
- Weakness
- CWE-918
- Published
- 2026-07-09
- Source
- github