CVE-2026-93749

NameCVE-2026-93749
Descriptionsource-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148404

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-postcss (PTS)bookworm8.4.20+~cs8.0.23-1+deb12u1vulnerable
trixie8.4.49+~cs9.2.32-1vulnerable
forky, sid8.5.28+~cs10.2.24-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-postcsssource(unstable)(unfixed)1148404

Notes

[trixie] - node-postcss <no-dsa> (Minor issue)
[bookworm] - node-postcss <postponed> (Minor issue)
https://github.com/7rulnik/source-map-js/issues/76
node-postcss embeds and provides node-source-map-js

Search for package or bug name: Reporting problems