VDB

CVE-2026-9358

CVE-2026-9358 PUBLISHED CVSS 5.3 MEDIUM

Reported by VulDB · Published May 24, 2026

A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."

EPSS 0.33% · 25.0th percentile

Risk Scores

CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.33%
25.0th percentile

Affected Products

VendorProductVersions
n/apostcss7.1.0, 7.1.1
n/apostcss7.1.0, 7.1.1

Timeline

  • May 24, 2026 EPSS Score
  • May 24, 2026 CVE Published
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score
  • May 29, 2026 EPSS Score
  • May 30, 2026 EPSS Score
  • May 31, 2026 EPSS Score
  • Jun 1, 2026 EPSS Score
  • Jun 2, 2026 Security Advisory
  • Jun 5, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›