Bug 2510719 (CVE-2026-69153) - CVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMappingURL
Summary: CVE-2026-69153 postcss: PostCSS: Information disclosure via crafted sourceMap...
Keywords:
Status: NEW
Alias: CVE-2026-69153
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2527420 2527421 2527424 2527425 2527428 2527429 2527432 2527433 2527434 2527435 2527436 2527438 2527439 2527440 2527441 2527442 2527443 2527444 2527445 2527447 2527448 2527449 2527450 2527452 2527454 2527456 2527458 2527459 2527462 2527463 2527467 2527468 2527469 2527470 2527471 2527472 2527473 2527422 2527423 2527437 2527446 2527451 2527453 2527455 2527457 2527460 2527461 2527465
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-03 18:01 UTC by OSIDB Bzimport
Modified: 2026-09-16 17:21 UTC (History)
159 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:57590 0 None None None 2026-08-20 16:07:52 UTC
Red Hat Product Errata RHSA-2026:68334 0 None None None 2026-09-16 17:21:38 UTC

Description OSIDB Bzimport 2026-08-03 18:01:24 UTC
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.23, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.23.

Comment 2 errata-xmlrpc 2026-08-20 16:07:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:57590 https://access.redhat.com/errata/RHSA-2026:57590

Comment 5 Jon Orris 2026-09-16 17:21:30 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:68334 https://access.redhat.com/errata/RHSA-2026:68334


Note You need to log in before you can comment on or make changes to this bug.