๐Ÿ” CVE Alert

CVE-2026-93752

HIGH 7.5

CSSOM through 0.5.0 Denial of Service via length Property

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter and trigger excessive memory allocation during cssText serialization, causing process termination.

CWE CWE-915
Vendor nv
Product cssom
Published Sep 18, 2026
Last Updated Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for nv cssom

Be the first to know when new high vulnerabilities affecting nv cssom are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

NV / CSSOM
0 โ‰ค 0.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NV/CSSOM/issues/119 github.com: https://github.com/NV/CSSOM github.com: https://github.com/NV/CSSOM/blob/00ec21868e12422581c81779135c2f1648441204/lib/CSSStyleDeclaration.js#L41-L56 github.com: https://github.com/NV/CSSOM/blob/00ec21868e12422581c81779135c2f1648441204/lib/CSSStyleDeclaration.js#L112-L124 vulncheck.com: https://www.vulncheck.com/advisories/cssom-through-0.5.0-denial-of-service-via-length-property

Credits

๐Ÿ” Wayde Shi (PayPal Cyber Security Team)