GHSA-w9m9-85wc-3x92

    Dashboard / Vulnerabilities / GHSA-w9m9-85wc-3x92

    GHSA-w9m9-85wc-3x92

    Published: 26 May 2026Last Modified: 10 Sept 2026
    Aliases:

    Summary: postcss-selector-parser allows denial of service through uncontrolled AST recursion

    Details: A vulnerability was determined in postcss-selector-parser before 6.1.3 and 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."

    Affected packages

    Package

    Name: postcss-selector-parser

    Purl: pkg:npm/postcss-selector-parser

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 6.1.0
    Fixed -6.1.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w9m9-85wc-3x92 | CVE-DB