The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern \/\*\s* sourceMappingURL=(.*).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2021-04-26T15:30:26.301297Z
Updated: 2024-09-16T23:26:53.744Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23382
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-04-26T16:15:07.330
Modified: 2023-08-08T14:22:24.967
Link: CVE-2021-23382
Redhat