Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44312

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS certificate—even entirely untrusted—will be accepted without validation. This vulnerability is fixed in 2.1.0 and 1.22.0.

A flaw was found in the css_parser Ruby gem prior to 2.1.0 and 1.22.0. When stylesheets are fetched over HTTPS, connections are opened with OpenSSL::SSL::VERIFY_NONE, so certificate validation is skipped. A network MITM attacker can present an untrusted certificate and inject or modify CSS returned to the parser.

Отчет

css_parser is vulnerable to MITM modification of HTTPS-fetched stylesheets because it disables TLS certificate verification (VERIFY_NONE). A remote network attacker positioned on the path can alter CSS content delivered to consumers that load remote stylesheets through the gem. Fixed in css_parser 2.1.0 and 1.22.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2477502css_parser: css_parser: Man-in-the-Middle attack due to improper HTTPS certificate validation

EPSS

Процентиль: 4%
0.00146
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
ubuntu
3 месяца назад

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS certificate—even entirely untrusted—will be accepted without validation. This vulnerability is fixed in 2.1.0 and 1.22.0.

CVSS3: 5.8
nvd
3 месяца назад

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS certificate—even entirely untrusted—will be accepted without validation. This vulnerability is fixed in 2.1.0 and 1.22.0.

CVSS3: 5.8
debian
3 месяца назад

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Pa ...

CVSS3: 5.8
github
3 месяца назад

CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content

EPSS

Процентиль: 4%
0.00146
Низкий

5.8 Medium

CVSS3