npm vulnerability intelligence

postcss NPM Package
Vulnerability Check

Tool for transforming styles with JS plugins

Moderate MIT v8.5.15
Vulnerability Analysis OSV Live

postcss

v8.5.15 · MIT · 225,473,101 dl/wk

Advisory Breakdown

Critical 0
High 0
Moderate 4
Low 0

Severity Rating

Moderate

4 advisories

Moderate

Weekly downloads

225,473,101

Total advisories

4

Latest version

8.5.15

License

MIT

Known advisories

OSV records for the npm ecosystem

4
GHSA-566m-qj78-rww5 CVE-2021-23382 moderate

Regular Expression Denial of Service in postcss

Affected: >=8.0.0 <8.2.13, >=0 <7.0.36 Fixed in: 8.2.13, 7.0.36 Updated Jan 14, 2025
View source
GHSA-7fh5-64p2-3v2j CVE-2023-44270 moderate

PostCSS line return parsing error

Affected: >=0 <8.4.31 Fixed in: 8.4.31 Updated Nov 4, 2025
View source
GHSA-hwj9-h5mp-3pm3 CVE-2021-23368 moderate

Regular Expression Denial of Service in postcss

Affected: >=7.0.0 <7.0.36, >=8.0.0 <8.2.10 Fixed in: 7.0.36, 8.2.10 Updated Jan 14, 2025
View source
GHSA-qx2v-qp2m-jg93 CVE-2026-41305 moderate

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Affected: >=0 <8.5.10 Fixed in: 8.5.10 Updated May 6, 2026
View source

Checked Jun 7, 2026, 5:41 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
postcss
Ecosystem
npm
Latest version
8.5.15
License
MIT
Weekly downloads
225,473,101

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/7/2026, 5:41:34 PM