CVE-2021-23368

Source
https://cve.org/CVERecord?id=CVE-2021-23368
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23368.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-23368
Aliases
Downstream
Related
  • SNYK-JAVA-ORGWEBJARSNPM-1244795
  • SNYK-JS-POSTCSS-1090595
Published
2021-04-12T14:15:14.257Z
Modified
2026-03-15T21:45:05.902020Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

References

Affected packages

Git / github.com/postcss/postcss

Affected ranges

Type
GIT
Repo
https://github.com/postcss/postcss
Events
Database specific
{
    "versions": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.36"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.2.10"
        }
    ]
}

Affected versions

7.*
7.0.0
7.0.1
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.2
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25
7.0.26
7.0.27
7.0.28
7.0.29
7.0.3
7.0.30
7.0.31
7.0.32
7.0.33
7.0.34
7.0.35
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23368.json"