CVE-2025-8263: prettier parser-postcss.js parseNestedCSS redos
Published Jul 28, 2025
·Updated
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Affected Software
1 affected component
Prettier prettier<=3.6.2
Event History
Jul 28, 2025
CVE Published
via MITRE·07:32 AM
Rejected
via MITRE·07:32 AM
Data Sourced
via NVD·08:15 AM
Description
Aug 2, 2025
Rejected
via MITRE·08:42 AM
Rejected
via NVD·09:15 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8263?
CVE-2025-8263 has been declared as problematic, indicating a significant security vulnerability.
2
How do I fix CVE-2025-8263?
To fix CVE-2025-8263, upgrade Prettier to version 3.6.3 or later.
3
Which versions of Prettier are affected by CVE-2025-8263?
CVE-2025-8263 affects Prettier versions up to and including 3.6.2.
4
What is the nature of the vulnerability in CVE-2025-8263?
CVE-2025-8263 involves inefficient regular expression complexity in the parseNestedCSS function.
5
Is there a workaround for CVE-2025-8263?
Currently, there are no known workarounds for CVE-2025-8263 other than upgrading the software.