To report a security vulnerability in Crass, please email ryan@wonko.com or use GitHub's Report a vulnerability feature.
Security: rgrove/crass
Security
SECURITY.md
-
Non-ASCII characters cause superlinear CPU consumptionGHSA-8vfg-2r28-hvhj published
Jun 25, 2026 by rgroveModerate -
A large number of adjacent CSS comments can trigger a SystemStackErrorGHSA-wwpr-jff3-395c published
Jun 25, 2026 by rgroveModerate -
Deeply nested CSS blocks and functions can trigger a SystemStackError or excessive memory usageGHSA-6jxj-px6v-747w published
Jun 25, 2026 by rgroveModerate -
Large numeric exponents cause CPU and memory denial of serviceGHSA-6wmf-3r64-vcwv published
Jun 25, 2026 by rgroveHigh
Learn more about advisories related to rgrove/crass in the GitHub Advisory Database