{"id":"UBUNTU-CVE-2021-23368","details":"The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.","modified":"2025-09-08T16:46:59Z","published":"2021-04-12T14:15:00Z","upstream":["CVE-2021-23368"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-23368"},{"type":"REPORT","url":"https://github.com/postcss/postcss/commit/8682b1e4e328432ba692bed52326e84439cec9e4"},{"type":"REPORT","url":"https://github.com/postcss/postcss/commit/b6f3e4d5a8d7504d553267f80384373af3a3dec5"},{"type":"REPORT","url":"https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595"},{"type":"REPORT","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244795"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-23368"}],"affected":[{"package":{"name":"node-postcss","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/node-postcss@8.4.6+~cs7.3.21-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.2.1+~cs5.3.23-8","8.4.5+~cs7.1.51-2","8.4.6+~cs7.3.21-1"],"ecosystem_specific":{"binaries":[{"binary_name":"node-postcss","binary_version":"8.4.6+~cs7.3.21-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-23368.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}