{"id":"CVE-2026-44312","aliases":["GHSA-ff6c-w6qf-7xqc"],"url":"https://o3.security/vulnerability/CVE-2026-44312","summary":"css_parser allows to MITM included https css urls","details":"css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS certificate—even entirely untrusted—will be accepted without validation. This vulnerability is fixed in 2.1.0 and 1.22.0.","published":"2026-05-14T16:15:04.907Z","modified":"2026-08-07T11:50:19.238328767Z","cvss":{"score":5.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"css_parser","fixedVersion":"2.1.0"},{"ecosystem":"RubyGems","name":"css_parser","fixedVersion":"1.22.0"}],"fix":{"url":"https://github.com/premailer/css_parser/commit/35e689c904225add78e0c488cf04bad052666449","label":"premailer/css_parser@35e689c"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44312.json"},{"type":"ADVISORY","url":"https://github.com/premailer/css_parser/security/advisories/GHSA-ff6c-w6qf-7xqc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44312"},{"type":"REPORT","url":"https://github.com/premailer/css_parser/issues/185"},{"type":"FIX","url":"https://github.com/premailer/css_parser/commit/35e689c904225add78e0c488cf04bad052666449"},{"type":"FIX","url":"https://github.com/premailer/css_parser/commit/e0c95d5abe91b237becb90ff316531a6547ada18"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:19.238328767Z"}}