CVE-2026-104844
Received Received - Intake

PostCSS Selector Parser Regular Expression ReDoS Vulnerability

Vulnerability report for CVE-2026-104844, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
postcss selector_parser 7.1.6
postcss postcss-selector-parser 7.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a CPU exhaustion issue in the postcss-selector-parser library affecting versions before 7.1.6. It occurs when parsing flat selectors like .a.a.a... or #a#a#a... due to inefficient parsing that results in quadratic time complexity instead of linear. The tokenizer treats . and # as non-word delimiters, causing repeated linear scans over index arrays during parsing, deduplication, and membership checks.

Detection Guidance

Detecting this vulnerability requires checking if your system uses postcss-selector-parser versions before 7.1.6. Run: npm list postcss-selector-parser or check package.json for version. If version is less than 7.1.6, the system is vulnerable.

Impact Analysis

This vulnerability can allow an attacker to cause a denial-of-service by sending a crafted selector that triggers excessive CPU usage. It only affects systems parsing untrusted selectors synchronously in request paths, such as CSS sanitizers or online playgrounds. A 400 KB selector could take ~34 seconds to parse on a modern laptop, severely degrading performance.

Mitigation Strategies

Upgrade postcss-selector-parser to version 7.1.6 or later immediately. If using npm, run: npm update postcss-selector-parser. For yarn, run: yarn upgrade postcss-selector-parser. Verify the update with npm list postcss-selector-parser.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104844. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart