CVE-2026-69153

Red Hat Security Advisory: Streams for Apache Kafka 3.2.1 release and security update

Beschreibung

PostCSS nimmt eine CSS-Datei und bietet eine API, um deren Regeln zu analysieren und zu modifizieren, indem die Regeln in einen abstrakten Syntaxbaum (AST) transformiert werden. Vor Version 8.5.19 konnte ein Angreifer, wenn `from` nicht gesetzt war, `PreviousMap.loadFile()` dazu bringen, eine unbeabsichtigte Quelltext-Kartendatei zu lesen, indem er einen absoluten oder directory-traversal `sourceMappingURL` bereitstellte. Die resultierenden Kartenquellen und -inhalte könnten dann der Anwendung ausgesetzt werden. Dieses Problem wurde in Version 8.5.19 behoben.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.3
Quelle: nvd-v4
38.0 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-12 19:35 UTC
CWE-22, CWE-200

Weakness-Klassen (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →
  • CWE-200Class

    Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-08-05 14:58 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    • CPE Configuration: OR *cpe:2.3:a:postcss:postcss:*:*:*:*:*:node.js:*:* versions up to (excluding) 8.5.23
    • Reference Type: GitHub, Inc.: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 Types: Patch
    • Reference Type: GitHub, Inc.: https://github.com/postcss/postcss/releases/tag/8.5.19 Types: Product, Release Notes
  2. CVE Modified2026-08-03 19:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
    • SSVC: {"id":"CVE-2026-69153","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
  3. New CVE Received2026-08-03 17:16 UTC· security-advisories@github.com
    • Affected: postcss
    • Description: PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.
    • CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-22

Betroffene Betriebssysteme

  • linux

    ubuntu / nettynoble

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    kafka2.8.0 – 3.9.2

  • apache

    kafka4.0.0 – 4.0.2

  • apache

    kafka4.1.0 – 4.1.2

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.26.0-0

  • eclipse

    vert.x4.0.0 – 4.5.29

  • eclipse

    vert.x5.0.0 – 5.1.4

  • go

    stdlib1.26.0-0

  • golang

    go1.26.0 – 1.26.2

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    go1.25.9

  • golang

    net0.55.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

Quellen & Referenzen

Verknüpfte CVEs

33 weitere CVEs anzeigen
IDCVE-2026-69153