StackRadar

CVE-2021-23368

Medium

Advisory

Published 10 May 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.035
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
31
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
1 of 1
affected package

Regular Expression Denial of Service in postcss

Carried by container images the latest versions of 31 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
postcssnpm7.0.5, 7.0.14, 7.0.17, 7.0.21+7 more7.0.36, 8.2.1031
OSV records
GHSA-hwj9-h5mp-3pm3

Charts affected

31 by stars
ChartLatestAffected imagesRadar Score
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
7.0.36

Open the chart page →

9,203
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
postcss@7.0.32
7.0.36

Open the chart page →

5,251
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@7.0.14
7.0.36

Open the chart page →

6,868
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
7.0.36

Open the chart page →

17,896
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
7.0.36

Open the chart page →

5,056
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
7.0.36

Open the chart page →

5,940
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
postcss@7.0.27
7.0.36

Open the chart page →

7,517
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
7.0.36

Open the chart page →

3,237
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
postcss@7.0.35
7.0.36

Open the chart page →

7,152
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
postcss@7.0.17
7.0.36

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
7.0.36

Open the chart page →

12,907
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
7.0.36

Open the chart page →

11,174
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.21
7.0.36

Open the chart page →

3,744
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
postcss@7.0.14
7.0.36

Open the chart page →

3,005
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
postcss@8.2.4
8.2.10

Open the chart page →

4,043
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
7.0.36

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
7.0.36

Open the chart page →

24,319
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
postcss@7.0.32
7.0.36
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
postcss@7.0.32
7.0.36
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
postcss@7.0.32
7.0.36
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
postcss@7.0.32
7.0.36

Open the chart page →

89,959
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
7.0.36

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
7.0.36

Open the chart page →

3,651
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
7.0.36

Open the chart page →

5,940
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
7.0.36

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
7.0.36

Open the chart page →

19,226
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postcss@7.0.21
7.0.36

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
postcss@7.0.25
7.0.36

Open the chart page →

6,684
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
7.0.36

Open the chart page →

27,465
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
postcss@7.0.32
7.0.36

Open the chart page →

6,026
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
7.0.36

Open the chart page →

3,638
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
postcss@7.0.21
7.0.36

Open the chart page →

3,696
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@7.0.35
7.0.36

Open the chart page →

2,460
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2021-23368.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
postcss@7.0.35
7.0.36

Open the chart page →

4,661

Container images carrying it

31 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
7.0.36
2
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
7.0.36
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
7.0.36
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
7.0.36
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
7.0.36
1
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.21
7.0.36
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
7.0.36
1
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
7.0.36
1
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
7.0.36
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@7.0.14
7.0.36
1
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@7.0.35
7.0.36
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
7.0.36
1
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
7.0.36
1
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
7.0.36
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
postcss@7.0.35
7.0.36
1
misskey/misskey:12.110.1e08b7c478093
postcss@7.0.32
7.0.36
1
mozilla/sentencecollector:2.0.91da6ff5c4895
postcss@7.0.25
7.0.36
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
postcss@8.2.4
8.2.10
1
ondrejsika/parking:latestb1fd497416c8
postcss@7.0.21
7.0.36
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
postcss@7.0.14
7.0.36
1
pysga1996/python-redis-web:latestfdeec30ad482
postcss@7.0.35
7.0.36
1
testhubio/testhub-frontend:on-preme86c2db53be8
postcss@7.0.27
7.0.36
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
postcss@7.0.32
7.0.36
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
postcss@7.0.32
7.0.36
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
postcss@7.0.32
7.0.36
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
postcss@7.0.32
7.0.36
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
7.0.36
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
postcss@7.0.32
7.0.36
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
postcss@7.0.17
7.0.36
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postcss@7.0.21
7.0.36
1
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
7.0.36
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.