PT-2026-85252 · Npm · Colord
CVE-2026-85062
·
Published
2026-09-03
·
Updated
2026-09-08
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Colord versions prior to 2.9.4
Description
Synchronous CSS color string matchers use an ambiguous numeric regular expression that allows digits to be divided between overlapping quantifiers in quadratically many ways when malformed input is rejected. An attacker can block the processing thread by providing a multi-kilobyte unbounded color string to the
colord(), getFormat(), isEqual(), mix(), or contrast() functions. This issue affects the parseRgbaString, parseHslaString, parseHwbaString, parseLchaString, and parseCmykaString matchers.Recommendations
Update to version 2.9.4.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Colord