Vulnerabilities/

Regular Expression Denial of Service in postcss

Severity:
Medium

Description

The package postcss versions before 7.0.36 or between 8.0.0 and 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern

Recommendation

Update the postcss package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
postcss
Anything's wrong? Let us know Last updated on September 08, 2023

This issue is available in SmartScanner Professional

See Pricing