PT-2026-85252 · Npm · Colord

CVE-2026-85062

·

Published

2026-09-03

·

Updated

2026-09-08

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Colord versions prior to 2.9.4
Description Synchronous CSS color string matchers use an ambiguous numeric regular expression that allows digits to be divided between overlapping quantifiers in quadratically many ways when malformed input is rejected. An attacker can block the processing thread by providing a multi-kilobyte unbounded color string to the colord(), getFormat(), isEqual(), mix(), or contrast() functions. This issue affects the parseRgbaString, parseHslaString, parseHwbaString, parseLchaString, and parseCmykaString matchers.
Recommendations Update to version 2.9.4.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85062
GHSA-2WM5-Q62R-HMRV

Affected Products

Colord