CVE-2026-53727Disclosure(premailer / css_parser)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch premailer css_parser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • css_parser

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
css_parser

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Ruby css_parser SSRF via @import remote fetch and redirect-to-file read (CVE-2026-53727) Ruby gem css_parser is vulnerable to server-side request forgery in CssParser::Parser#read_remote_file and related code paths that automatically follow @import URLs without adequate scheme or network-range filtering. The root cause is improper input validation and unsafe URL/redirect handling that allows access to private, loopback, and link-local targets and can be coerced into file:// via redirects. An attacker exploits this by supplying crafted CSS (or a URL to attacker-controlled CSS) that the application parses, causing the server to make outbound requests and follow redirect hops under the app’s network identity without needing elevated privileges beyond reaching the CSS processing path. Impact includes SSRF for internal service discovery/access and potential local file reads leading to sensitive data exposure when parsed/serialized by downstream consumers (e.g., Premailer output). 👉 Affected: css_parser < 3.0.0 | Upgrade to 3.0.0

    Post summary

    CVE‑2026‑53727 exposes SSRF and potential local file read in the Ruby css_parser gem via @import handling; upgrading to version 3.0.0 mitigates the issue.

    00000108
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppremailercss_parser2.2.0ruby-

Explore more