CVE-2026-9358

ADVISORY - github

Summary

A vulnerability was determined in postcss-selector-parser before 6.1.3 and 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."

EPSS Score: 0.00325 (0.252)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Resource Shutdown or Release

Uncontrolled Recursion

ADVISORY - github

Improper Resource Shutdown or Release


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in