CVE-2026-14651 Details
Description
A vulnerability has been found in connorskees grass up to 0.13.4. The impacted element is the function grass_compiler::selector::extend/grass_compiler::evaluate::visitor. The manipulation leads to denial of service. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The project maintainer explains: "DoS vulnerabilities are generally fine in Sass compilers -- they are trivially possible with recursive functions, infinite loops, nested mixins, etc. The description here is wrong. Compile time is not expected to be linear relative to the input, and the @extend algorithm is definitionally exponential."
A denial-of-service vulnerability has been identified in Connorskees Grass versions through 0.13.4. The issue arises in the 'grass_compiler::selector::extend' and 'grass_compiler::evaluate::visitor' functions, where certain nesting patterns of parent-selector references can cause super-linear expansion of selectors. This vulnerability can be exploited locally, leading to excessive memory and CPU usage during compilation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 4, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/connorskees/grass/ | [email protected] | ProductSource CodeVendor |
| https://github.com/connorskees/grass/issues/117 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-14651 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/846667 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376164 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/376164/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| connorskees grass | <= 0.13.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 4, 2026 | New CVE Received | [email protected] |
Volerion