cbcvebase.

Postcss vulnerabilities

6 known vulnerabilities affecting postcss/postcss.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-45623P3HIGHCVSS 7.5fixed in 8.5.122026-07-27
CVE-2026-45623 [HIGH] CWE-22 CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traver
ghsanvd
CVE-2021-23382P3HIGHCVSS 7.5fixed in 7.0.36≥ 8.0.0, < 8.2.13+1 more2021-04-26
CVE-2021-23382 [HIGH] CWE-1333 CVE-2021-23382: The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).
ghsanvdosv
CVE-2026-41305P4MEDIUMCVSS 6.1fixed in 8.5.102026-04-24
CVE-2026-41305 [MEDIUM] CWE-79 CVE-2026-41305: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `` tags, `` in CSS values breaks out of the style context, enabl
ghsanvd
CVE-2021-23368P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.36≥ 8.0.0, < 8.2.10+2 more2021-04-12
CVE-2021-23368 [MEDIUM] CVE-2021-23368: The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Serv The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
ghsanvdosv
CVE-2023-44270P4MEDIUMCVSS 5.3fixed in 8.4.312023-09-29
CVE-2023-44270 [MEDIUM] CWE-74 CVE-2023-44270: An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite bei
ghsanvdosv
CVE-2026-9358P4MEDIUMCVSS 5.3v7.1.0v7.1.12026-05-24
CVE-2026-9358 [MEDIUM] CWE-674 postcss AST Serialization container.js toString recursion postcss AST Serialization container.js toString recursion A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains,
cvelistv5
Postcss vulnerabilities | cvebase