Executive brief
PostCSS is a widely-used JavaScript tool for transforming CSS stylesheets using plugins. A flaw in PostCSS's source map parsing allows an attacker to supply malicious CSS containing carefully-crafted sourceMappingURL comments that cause the regex engine to consume excessive CPU, freezing the application. Any service that parses untrusted CSS files—such as web builders, CSS processors, or build pipelines—could be rendered unavailable.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in the getAnnotationURL() and loadAnnotation() functions within lib/previous-map.js. The vulnerable regex pattern `/\*\s*#\s*sourceMappingURL=(.*)` exhibits catastrophic backtracking when processing malicious input—specifically, repeated "/*# sourceMappingURL=" sequences without a closing comment. An attacker can craft a CSS file with nested sourceMappingURL markers that cause the regex engine to exponentially increase backtracking attempts (e.g., 14 repeated markers trigger over 65,000 regex steps), consuming all available CPU and blocking legitimate processing. The attack requires only network access to a service that calls postcss.parse() on untrusted input; no authentication or user interaction is needed. Patches are available in versions 7.0.36 and 8.2.13 or later.
Affected products
- PostCSS postcss before 7.0.36 or 8.0.0 to 8.2.13
Timeline
- 2021-04-26: disclosed
- 2021-06-11: patched: version 7.0.36 released
- 2021-11-04: patched: version 8.2.13 released (inferred)