Repository navigation
Security: premailer/css_parser
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Arbitrary local-file read via attacker-controlled `@import` into `load_file!` (the `base_dir` branch of `add_block!`) - incomplete fix of GHSA-9pmc-p236-855hGHSA-w3mx-4vv9-hjpg published
Oct 7, 2026 by grosserModerate -
expand_shorthand! regex (RE_FUNCTIONS) backtracks exponentially on an unclosed CSS function valueGHSA-84w7-hpvm-rxx2 published
Sep 20, 2026 by grosserModerate -
SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`GHSA-9pmc-p236-855h published
Jun 1, 2026 by grosserHigh -
css_parser allows to MITM included https css urlsGHSA-ff6c-w6qf-7xqc published
May 1, 2026 by grosserModerate
Learn more about advisories related to premailer/css_parser in the GitHub Advisory Database