npm vulnerability intelligence

postcss NPM Package
Vulnerability Check

Tool for transforming styles with JS plugins

High severity MIT v8.5.26
Vulnerability Analysis OSV Live

postcss

v8.5.26 · MIT · 271,618,690 dl/wk

Advisory Breakdown

Critical 0
High 2
Moderate 5
Low 0

Severity Rating

High severity

7 advisories

High severity

Weekly downloads

271,618,690

Total advisories

7

Latest version

8.5.26

License

MIT

Known advisories

OSV records for the npm ecosystem

7
GHSA-566m-qj78-rww5 CVE-2021-23382 moderate

Regular Expression Denial of Service in postcss

Affected: >=8.0.0 <8.2.13, >=0 <7.0.36 Fixed in: 8.2.13, 7.0.36 Updated Jan 14, 2025
View source
GHSA-6g55-p6wh-862q CVE-2026-45623 high

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

Affected: >=0 <8.5.12 Fixed in: 8.5.12 Updated Jul 28, 2026
View source
GHSA-7fh5-64p2-3v2j CVE-2023-44270 moderate

PostCSS line return parsing error

Affected: >=0 <8.4.31 Fixed in: 8.4.31 Updated Jul 8, 2026
View source
GHSA-fxqj-rqcc-2cmp CVE-2026-69153 moderate

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

Affected: >=0 <8.5.23 Fixed in: 8.5.23 Updated Aug 4, 2026
View source
GHSA-hwj9-h5mp-3pm3 CVE-2021-23368 moderate

Regular Expression Denial of Service in postcss

Affected: >=7.0.0 <7.0.36, >=8.0.0 <8.2.10 Fixed in: 7.0.36, 8.2.10 Updated Jan 14, 2025
View source
GHSA-qx2v-qp2m-jg93 CVE-2026-41305 moderate

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Affected: >=0 <8.5.10 Fixed in: 8.5.10 Updated May 6, 2026
View source
GHSA-r28c-9q8g-f849 high

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

Affected: >=0 <8.5.18 Fixed in: 8.5.18 Updated Jul 28, 2026
View source

Checked Aug 12, 2026, 7:45 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
postcss
Ecosystem
npm
Latest version
8.5.26
License
MIT
Weekly downloads
271,618,690

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 8/12/2026, 7:45:01 PM