The npm package postcss
from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
{ "nvd_published_at": "2021-04-12T14:15:00Z", "github_reviewed_at": "2021-05-07T17:26:38Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-400" ] }