Bug 2481006 (CVE-2026-9358)

Summary: CVE-2026-9358 postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abrianik, abuckta, akostadi, alcohan, alizardo, amasferr, anpicker, anthomas, anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bdettelb, bmaxwell, boliveir, bparees, brasmith, bstansbe, cdrage, chfoley, cmah, cmyers, cochase, dbruscin, dfreiber, dhanak, dkuc, dlofthou, dmayorov, dnakabaa, doconnor, dranck, drichtar, drosa, drow, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, erezende, ewittman, fdeutsch, fmariani, ggainey, ggrzybek, gmalinko, gotiwari, gparvin, hasun, ibek, ibolton, istudens, ivassile, iweiss, janstey, jbalunas, jburrell, jchui, jfula, jgrulich, jhe, jhorak, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jowilson, jraez, jrokos, juwatts, jwong, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, lcouzens, lphiri, manissin, mcarlett, mhulan, mnovotny, mosmerov, mposolda, mstipich, msvehla, mvyas, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, orabin, oramraz, osousa, pahickey, pantinor, parichar, pberan, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, prwatson, psrna, ptisnovs, rchan, rexwhite, rgodfrey, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sausingh, sdawley, sdoran, sfeifer, simaishi, slucidi, smaestri, smallamp, smcdonal, smullick, sseago, ssilvert, stcannon, sthirugn, sthorger, stirabos, swoodman, syedriko, tasato, tcunning, teagle, thason, thjenkin, tmalecek, tpopela, tsedmik, ttakamiy, vdosoudi, veshanka, vkumar, vmuzikar, watson-tool-maintainers, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in postcss. A remote attacker could exploit a vulnerability in the `toString` function of the AST Serialization component by executing a manipulation, leading to uncontrolled recursion. This uncontrolled recursion can result in a Denial of Service (DoS) condition, making the affected system unavailable.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-24 07:01:11 UTC
A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."