Executive brief
postcss is a popular JavaScript tool for parsing and transforming CSS code, widely used in web development. A regular expression flaw in its source map parsing can cause the application to hang or consume excessive CPU resources when processing maliciously crafted input, leading to denial of service attacks against applications using the library.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in postcss versions 7.0.0 through 7.0.35 and 8.0.0 through 8.2.9, specifically in the source map parsing component (previous-map.es6). The vulnerability arises from a poorly constructed regular expression that exhibits catastrophic backtracking behavior when processing input with certain patterns. An attacker can supply a maliciously crafted CSS file with a specially crafted source map to trigger excessive regex engine resource consumption, causing the application to hang or become unresponsive. The attack requires network reachability to deliver the malicious CSS/source map to an application using postcss, with no authentication required. Patches are available in versions 7.0.36 and 8.2.10 and later.
Affected products
- postcss postcss 7.0.0 through 7.0.35, 8.0.0 through 8.2.9
Timeline
- 2021-04-12: disclosed
- 2021-05-10: advisory
- 2021-05-07: patched