ZeroHour

CVE-2021-23368

PoC ×2
CVSS 3.1
5.3 medium
EPSS
4%p89
Published
()
Modified
Description

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

Vendors
postcss
Products
postcss
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.