Uncontrolled Recursion in postcss-selector-parser - CVE-2026-9358
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the toString function in src/selectors/container.js of the AST serialization component when serializing a manipulated AST. A remote attacker can execute a manipulation to cause a denial of service.
User interaction is required.
Affected software
Nautobot
How to mitigate CVE-2026-9358
Nautobot - addressed in versions 2.4.42, 3.2.5