Lucene search

K
osvGoogleOSV:CVE-2021-23382
HistoryApr 26, 2021 - 4:15 p.m.

CVE-2021-23382

2021-04-2616:15:07
Google
osv.dev
7

6.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.6%

The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern /*\s* sourceMappingURL=(.*).

6.6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.6%