Description
The npm package postcss from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
Recommendation
Update the postcss package to the latest compatible version. Followings are version details:
Affected version(s): **>= 8.0.0, < 8.2.10 >= 7.0.0, < 7.0.36** Patched version(s): **8.2.10 7.0.36**
References
Could your website be exposed too?
SmartScanner can check your website for Regular Expression Denial of Service in postcss - postcss and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service in postcss - CVE-2021-23382
- Regular expression denial of service in jquery-validation - jquery-validation - CVE-2021-43306
- Regular expression Denial of Service in multiple packages - @ckeditor/ckeditor5-font - CVE-2021-21391
- html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - html-parse-stringify - CVE-2021-23346
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


