Postcss
Postcss · 7 CVEs
CVE-2026-73646
HIGH
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
Aug 17, 2026
CVE-2026-69153
MEDIUM
PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from`…
Aug 3, 2026
CVE-2026-45623
CRITICAL
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
Jul 27, 2026
CVE-2026-41305
MEDIUM
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
Apr 24, 2026
CVE-2023-44270
MEDIUM
PostCSS: Improper input validation in PostCSS
Sep 29, 2023
CVE-2021-23382
HIGH
Regular Expression Denial of Service (ReDoS)
Apr 26, 2021
CVE-2021-23368
MEDIUM
Regular Expression Denial of Service (ReDoS)
Apr 12, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-73646 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure | HIGH | 0.53% | Aug 17, 2026 |
| CVE-2026-69153 | PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset | MEDIUM | 0.45% | Aug 3, 2026 |
| CVE-2026-45623 | PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments | CRITICAL | 0.61% | Jul 27, 2026 |
| CVE-2026-41305 | PostCSS has XSS via Unescaped </style> in its CSS Stringify Output | MEDIUM | 0.26% | Apr 24, 2026 |
| CVE-2023-44270 | PostCSS: Improper input validation in PostCSS | MEDIUM | 0.97% | Sep 29, 2023 |
| CVE-2021-23382 | Regular Expression Denial of Service (ReDoS) | HIGH | 2.56% | Apr 26, 2021 |
| CVE-2021-23368 | Regular Expression Denial of Service (ReDoS) | MEDIUM | 3.51% | Apr 12, 2021 |
Showing 1 to 7 of 7 CVEs