StackRadar

CVE-2023-44270

Medium

Advisory

Published 29 Sept 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
115
of 17,781 indexed, latest versions
Container images
108
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS line return parsing error

Carried by container images the latest versions of 115 of 17,781 indexed charts deploy, on 108 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+31 more8.4.31107
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-7fh5-64p2-3v2jUBUNTU-CVE-2023-44270

Charts affected

115 by stars
ChartLatestAffected imagesRadar Score
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
8.4.31

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@7.0.39
8.4.31

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.4.31

Open the chart page →

3,143
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
postcss@8.4.14
8.4.31

Open the chart page →

4,820
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
postcss@7.0.21
8.4.31

Open the chart page →

3,696
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.4.31

Open the chart page →

7,574
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.4.31

Open the chart page →

2,460
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.4.31

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.4.31

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
postcss@6.0.23
8.4.31

Open the chart page →

3,881
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
postcss@8.4.6
8.4.31

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
postcss@7.0.39
8.4.31

Open the chart page →

20,270
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
postcss@7.0.35
8.4.31

Open the chart page →

4,661
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
postcss@6.0.23
8.4.31

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2023-44270.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.4.31

Open the chart page →

22,665

Container images carrying it

108 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@7.0.39
8.4.31
1
library/ghost:4.37.0767230c0f263
postcss@8.4.6
8.4.31
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
postcss@7.0.36
8.4.31
1
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
8.4.31
1
linuxserver/overseerr:1.35.06108ed066d4a
postcss@8.4.14
8.4.31
1
lissy93/dashy:2.0.51991f7be5ed0
postcss@7.0.39
8.4.31
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
postcss@8.4.14
8.4.31
1
lsstsqre/squareone:0.4.09ded78e7fe03
postcss@8.2.13
8.4.31
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
postcss@8.3.5
8.4.31
1
misskey/misskey:12.110.1e08b7c478093
postcss@8.3.11
8.4.31
1
mitchxxx/amazon:214e72480ec63a
postcss@8.4.23
8.4.31
1
mozilla/sentencecollector:2.0.91da6ff5c4895
postcss@7.0.25
8.4.31
1
n8nio/n8n:0.212.0a9195bc499a3
postcss@8.4.21
8.4.31
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
postcss@8.2.4
8.4.31
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
postcss@8.4.21
8.4.31
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
postcss@8.4.21
8.4.31
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
postcss@8.4.5
8.4.31
1
ondrejsika/parking:latestb1fd497416c8
postcss@7.0.21
8.4.31
1
ooghenekaro/amazon:latest03394ba1d6d8
postcss@7.0.39
8.4.31
1
openbas/caldera-server:5.1.0a277796d9724
postcss@8.4.16
8.4.31
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
postcss@8.4.14
8.4.31
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
postcss@7.0.14
8.4.31
1
phntom/codimd:2.4.31b9aafbb62e6
postcss@6.0.23
8.4.31
1
polonel/trudesk:1.2.60cf6513f6fe3
postcss@8.4.6
8.4.31
1
pysga1996/python-redis-web:latestfdeec30ad482
postcss@7.0.35
8.4.31
1
samajh/alprfrontend:latest05ef4fddbb75
postcss@7.0.39
8.4.31
1
sharanalwar/redchef-frontend:latest5e82950b16b7
postcss@6.0.23
8.4.31
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
postcss@6.0.23
8.4.31
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
postcss@6.0.23
8.4.31
1
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.4.31
1
testhubio/testhub-frontend:on-preme86c2db53be8
postcss@7.0.27
8.4.31
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
postcss@8.4.12
8.4.31
1
ubercadence/web:v3.29.58564a5b44a6d
postcss@6.0.23
8.4.31
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
postcss@7.0.39
8.4.31
1
vlebediantsev/notes-admin-front:latest007c6670ff48
postcss@8.4.27
8.4.31
1
vlebediantsev/notes-project-front:latest945675fd2636
postcss@7.0.39
8.4.31
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
postcss@7.0.39
8.4.31
1
winfred008/amazon:910a68de5b398
postcss@8.4.23
8.4.31
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
postcss@8.4.14
8.4.31
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
postcss@8.4.14
8.4.31
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
postcss@7.0.32
8.4.31
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
postcss@7.0.32
8.4.31
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
postcss@7.0.32
8.4.31
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
postcss@7.0.32
8.4.31
1
ghcr.io/data-fair/metrics:0a8d40779eeae
postcss@7.0.39
8.4.31
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
postcss@7.0.39
8.4.31
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
postcss@6.0.23
8.4.31
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
8.4.31
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
postcss@8.4.14
8.4.31
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
postcss@7.0.32
8.4.31
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.