PT-2026-42916 · Npm · Postcss

Bx33661

·

Published

2026-05-24

·

Updated

2026-05-24

·

CVE-2026-9358

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions postcss versions prior to 7.1.2
Description An issue exists in the AST Serialization component within the toString() function of the src/selectors/container.js file. A remote attacker can perform a manipulation that leads to uncontrolled recursion, potentially causing a denial of service. This risk is primarily applicable to server-side environments processing user-generated CSS.
Recommendations Update to version 7.1.2 or later. As a temporary workaround, restrict the processing of user-generated CSS through the toString() function in the src/selectors/container.js file.

Exploit

Improper Resource Release

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2026-9358

Affected Products

Postcss