Sceawere

Vulnerability Detail

CVE-2026-104844UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PostCSS Selector Parser DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
7h ago
Vendor
postcss
Product
postcss-selector-parser
Attack Type
CWE-400: Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-02T16:16:46.917Z",
  "pubdate": "2026-10-02T16:16:46.917Z",
  "executiveSummary": "A denial of service (DoS) vulnerability exists in the PostCSS Selector Parser library prior to version 7.1.6. The issue arises from an algorithmic complexity vulnerability within the parser's tokenization and deduplication processes, specifically involving the processing of class and ID indexes.\nWhen the parser processes a crafted, flat selector containing a large number of class or ID designators without nested structures, it performs repetitive linear scanning. This behavior results in quadratic parsing time relative to the number of indexes processed, allowing a single thread to be occupied indefinitely.\nAn attacker capable of submitting untrusted CSS selectors to an application that parses them synchronously can exploit this flaw to consume excessive CPU resources. This can lead to a complete denial of service for the hosting application, while ordinary build-time parsing remains unaffected.",
  "technicalDetails": "The root cause of the vulnerability resides within the 'splitWord()' function located in 'src/parser.js' of the PostCSS Selector Parser package. During the tokenization phase, the parser splits input strings into manageable tokens. However, because the period ('.') and hash ('#') characters—which denote CSS classes and IDs respectively—are not defined as tokenizer word delimiters, the 'splitWord()' function handles a flat selector containing numerous consecutive class or ID identifiers as a single, massive word token containing multiple index pointers.\nThis word token carries an array representing numerous class or ID indexes. When the parser attempts to resolve and sanitize this token, it executes several processing passes over these index arrays. Specifically, the 'uniqs()' deduplication function and the subsequent per-index membership checks for classes and IDs are executed sequentially. Because of the architectural design of these passes, the parser repeatedly performs linear scans across the entire index array for every single index present. Furthermore, an independent processing pass designed to filter Sass-interpolation syntax executes its own repeated linear scanning over the same data structures. Consequently, the combination of these repetitive linear scanning operations scales the computational complexity of the parsing process quadratically (O(N^2)) relative to the number of class or ID indexes contained within the single word token.\nA malicious actor can exploit this behavior by crafting a highly specific CSS selector string containing a flat sequence of hundreds or thousands of class or ID designators without any hierarchy (for example, '.class1.class2.class3...'). When this payload is delivered to a target application that processes CSS selectors synchronously on an exposed network request path, the thread block occurs immediately, creating a CPU exhaustion state.\nBecause the JavaScript runtime environment is typically single-threaded, occupying the parser thread with a quadratic-time operation starves the event loop, preventing the application from handling concurrent incoming requests and leading to service degradation or complete outages.\nStandard defensive mechanisms within the parser, such as the 'maxNestingDepth' security guard, are entirely bypassed by this attack vector. The 'maxNestingDepth' attribute is designed to limit deeply nested structures, but the hostile selector in this exploit scenario is entirely flat, possessing a nesting depth of zero. This allows the payload to bypass structural constraints while still triggering the resource exhaustion flaw. The vulnerability is fully mitigated in version 7.1.6 by refactoring tokenization boundaries and optimizing deduplication."
}
CVE-2026-104844: PostCSS Selector Parser DoS (MEDIUM Severity, CVSS: 5.9) | Sceawere