VDB
CVE-2026-9358
CVE-2026-9358
PUBLISHED
CVSS 5.3 MEDIUM
Reported by VulDB · Published May 24, 2026
A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."
EPSS 0.33% · 25.0th percentile
Risk Scores
CVSS 4.0
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.33%
25.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | postcss | 7.1.0, 7.1.1 |
| n/a | postcss | 7.1.0, 7.1.1 |
Timeline
- May 24, 2026 EPSS Score
- May 24, 2026 CVE Published
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
- May 28, 2026 EPSS Score
- May 29, 2026 EPSS Score
- May 30, 2026 EPSS Score
- May 31, 2026 EPSS Score
- Jun 1, 2026 EPSS Score
- Jun 2, 2026 Security Advisory
- Jun 5, 2026 EPSS Score
References
- VDB-365321 | postcss AST Serialization container.js toString recursion vdb-entrytechnical-description
- VDB-365321 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- Submit #813080 | postcss-selector-parser postcss <= 7.1.1 CWE-674: Uncontrolled Recursion third-party-advisory
- exploit