The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
{ "binaries": [ { "binary_name": "node-postcss", "binary_version": "8.4.6+~cs7.3.21-1" } ] }