Executive brief
The css_parser Ruby library, used for processing CSS files, contains a security flaw in how it handles remote files and imports. An attacker can provide a malicious CSS file that forces the server to make unauthorized network requests to internal systems or read sensitive local files from the server's hard drive. This could lead to the exposure of private configuration data, internal credentials, or other confidential information stored on the host system.
Technical details
The vulnerability exists in `CssParser::Parser#read_remote_file` (and by extension `load_uri!` and `add_block!`) because it fails to validate schemes, hosts, or IP addresses before making HTTP/HTTPS requests. It lacks protection against loopback, link-local, and RFC-1918 addresses, enabling SSRF. Furthermore, the parser recursively follows redirects without re-validating the URI scheme. An attacker can provide a remote CSS URL that returns an HTTP 3xx redirect to a `file://` URI, allowing the attacker to read arbitrary local files accessible to the Ruby process. The issue is exacerbated because the parser attempts to decompress gzipped responses, potentially leading to decompression bomb DoS attacks. The vulnerability is fixed in version 3.0.0 by routing remote fetches through `ssrf_filter` and gating `file://` URIs behind an opt-in flag.
Affected products
- premailer css_parser >= 2.2.0, < 3.0.0
Timeline
- 2026-05-28: patched: Fixes committed to repository
- 2026-06-01: advisory: GitHub Security Advisory published
- 2026-07-17: disclosed: CVE published to NVD
References
- https://github.com/premailer/css_parser/commit/7d2ddf0189cd54b54f378f59daefa10cb036e476
- https://github.com/premailer/css_parser/commit/e0a151458b2a801ae265ba420862ef8b1127b3ae
- https://github.com/premailer/css_parser/releases/tag/v3.0.0
- https://github.com/premailer/css_parser/security/advisories/GHSA-9pmc-p236-855h