A vulnerability was determined in postcss up to 7.1.1....
Low severity
Unreviewed
Published
May 26, 2026
to the GitHub Advisory Database
•
Updated May 26, 2026
Description
Published by the National Vulnerability Database
May 24, 2026
Published to the GitHub Advisory Database
May 26, 2026
Last updated
May 26, 2026
A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."
References