Vulnerabilities/

Regular Expression Denial of Service in postcss (GHSA-hwj9-h5mp-3pm3)

Severity:
Medium

Description

The npm package postcss from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

Recommendation

Update the postcss package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
postcss
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing