PostCSS is a JavaScript-based CSS transformation tool widely embedded in build pipelines and web development toolchains, where its plugin architecture and text-processing role create a surface for downstream injection attacks. The durable signal centers on output-neutralization and regular-expression handling, reflecting the risks inherent to parsing and transforming stylesheets without proper escaping of special elements and the computational complexity of validation patterns. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postcss over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23382HIGH The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable | Apr 26, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-44270MEDIUM An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it | Sep 29, 2023 | 5.3 | 19 | NO | NO |
CVE-2021-23368MEDIUM The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing. | Apr 12, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postcss.
Media articles that mention a CVE ID that affects a product developed by Postcss — matched by CVE ID, not by vendor name.