CVE-2026-14651

Description

A flaw was found in grass, a Sass compiler. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by manipulating specific functions within the compiler, such as grass_compiler::selector::extend or grass_compiler::evaluate::visitor. This can lead to the compiler becoming unresponsive or crashing, impacting the availability of the service.

Statement

This Low impact denial of service (DoS) vulnerability in the grass Sass compiler requires local access to exploit. While a DoS is possible through manipulating compiler functions, such as grass_compiler::selector::extend or grass_compiler::evaluate::visitor, this typically affects build or development environments where local access is already assumed, limiting its broader impact on Red Hat products.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Amplification

An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.

Frequently Asked Questions

Want to get errata notifications? Sign up here.