{"id":"GHSA-rj75-hqrm-r3gf","summary":"PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion","details":"### Impact\n\n`.` and `#` are not word delimiters in the tokenizer, so a flat selector such as\n`.a.a.a...` reaches `splitWord()` as a single word token carrying n class or id\nindexes. Three passes scanned those index arrays linearly for every index,\nmaking the parse O(n^2) in the number of indexes rather than in input length:\n`uniqs()`, the `indices.forEach` loop, and the Sass-interpolation filter.\nParsing a 400 KB flat selector took ~34 s on a modern laptop, fully occupying a\nsingle thread. A benign selector of identical byte size parses in tens of\nmilliseconds, so the cost is driven by the index count, not the input size.\nThe nesting depth of such a selector is 0, so the `maxNestingDepth` guard added\nin 7.1.3 offers no protection.\n\nReachability is deployment dependent. Only consumers that parse untrusted,\nattacker-supplied selectors synchronously in a request path are exposed, for\nexample CSS sanitizers, CSS-in-JS services and online playgrounds. Ordinary\nbuild-time use on trusted sources is not affected.\n\n### Patches\n\nFixed in 7.1.6. The three passes now use Set membership tests, making parsing\nlinear in the number of indexes. There is no behaviour change: parsing is\nbyte-identical on a differential corpus of 8413 selectors.\n\n### Workarounds\n\nCap the size of selectors accepted from untrusted sources before parsing.","aliases":["CVE-2026-104844"],"modified":"2026-10-05T23:00:05.308008424Z","published":"2026-10-05T22:53:54Z","database_specific":{"cwe_ids":["CWE-400","CWE-407"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-05T22:53:54Z","nvd_published_at":"2026-10-02T16:16:46Z"},"references":[{"type":"WEB","url":"https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844"},{"type":"WEB","url":"https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd"},{"type":"PACKAGE","url":"https://github.com/postcss/postcss-selector-parser"},{"type":"WEB","url":"https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6"}],"affected":[{"package":{"name":"postcss-selector-parser","ecosystem":"npm","purl":"pkg:npm/postcss-selector-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-rj75-hqrm-r3gf/GHSA-rj75-hqrm-r3gf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}