StackRadar

CVE-2026-104844

Medium

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
767
of 18,035 indexed, latest versions
Container images
768
deployed by those charts
Fix available
1 of 1
affected package

PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion

Carried by container images the latest versions of 767 of 18,035 indexed charts deploy, on 768 images.

Affected packageAffected versionsFixed inImages
postcss-selector-parsernpm2.2.3, 3.1.1, 3.1.2, 5.0.0+21 more7.1.6768
OSV records
GHSA-rj75-hqrm-r3gf
Trending
Rank 22 in indexed charts, since 6 Oct 2026. See the ranking →

Charts affected

767 by stars
ChartLatestAffected imagesRadar Score
agenthttpmqttassist-iot-composite-services1.0.01 of 1See more

agenthttpmqtt assist-iot-composite-services 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/composite-services-manager_agent-http-mqtt:latest16d21bc5e42e
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

1,274
agentmqtthttpassist-iot-composite-services1.0.01 of 1See more

agentmqtthttp assist-iot-composite-services 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/composite-services-manager_agent-mqtt-http:latest27d58b8911cd
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

1,274
dltkvassist-iot-data-integrity-verification0.2.01 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

196,876
dltflassist-iot-dlt-based-fl0.2.01 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.1.0c8a170683be7
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

196,876
multilink-clientassist-iot-multi-link-client-app1.0.01 of 2See more

multilink-client assist-iot-multi-link-client-app 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/multi-link_client:latestcf048365d042
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

1,577
multilink-serverassist-iot-multi-link-server-app1.0.01 of 2See more

multilink-server assist-iot-multi-link-server-app 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/multi-link_server:latestf38c76a4c960
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

1,050
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
postcss-selector-parser@6.0.11
7.1.6

Open the chart page →

92,801
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
postcss-selector-parser@6.0.15
7.1.6

Open the chart page →

36,223
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

10,664
nas-appsawesomeVerified publisher2.0.02 of 8See more

nas-apps awesome 2.0.0

2 of the 8 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
postcss-selector-parser@6.0.6
7.1.6
wettyoss/wetty:latestc52dac712353
postcss-selector-parser@7.1.1
7.1.6

Open the chart page →

7,524
awesomeblessingappawesomeblessingapp1.1.01 of 1See more

awesomeblessingapp awesomeblessingapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
bnwokoye/nodejswebapp:latest74de7dc7ebfb
postcss-selector-parser@6.0.11
7.1.6

Open the chart page →

1,369
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

1,989
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
fosrl/pangolin:latest00cfb631097a
postcss-selector-parser@7.1.1
7.1.6

Open the chart page →

2,194
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

2,619
immichbear0.1.11 of 2See more

immich bear 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
postcss-selector-parser@6.1.4
7.1.6

Open the chart page →

7,816
myhelmappbelihelmapp1.1.01 of 1See more

myhelmapp belihelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
belirta/beli-docker:v1.0.0f65ad0e23b4d
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

1,289
http-debugbicarus-labs0.1.01 of 1See more

http-debug bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
bicarus/http-https-echo:2785dd6a7e805e
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

954
bluerange-mosquittobluerangeOfficialVerified publisher1.1.01 of 1See more

bluerange-mosquitto bluerange 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:2690a4e5b92cc6
postcss-selector-parser@7.1.4
7.1.6

Open the chart page →

268
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
postcss-selector-parser@6.1.2
7.1.6
sysnet4admin/colosseum-prm:log5802bfcd7fed
postcss-selector-parser@6.1.2
7.1.6

Open the chart page →

30,100
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
postcss-selector-parser@7.1.4
7.1.6
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
postcss-selector-parser@6.1.2
7.1.6

Open the chart page →

79,315
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

1,489
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
postcss-selector-parser@6.1.2
7.1.6

Open the chart page →

1,476
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latest68b19aee1c64
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

16,917
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

1,487
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

1,487
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

8,815
ghostchart-ghost0.1.61 of 2See more

ghost chart-ghost 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
library/ghost:6.65.0-alpine3.23fea3264f902e
postcss-selector-parser@7.1.1
7.1.6

Open the chart page →

1,762
audiobookshelfcharts-derwitt-devVerified publisher1.1.31 of 1See more

audiobookshelf charts-derwitt-dev 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.37.1581d68b2a6fc
postcss-selector-parser@7.1.4
7.1.6

Open the chart page →

1,456
ddb-proxycharts-derwitt-devVerified publisher1.3.01 of 1See more

ddb-proxy charts-derwitt-dev 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

888
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

2,676
audiobookshelfchristianhuthVerified publisher2.5.11 of 1See more

audiobookshelf christianhuth 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.37.1581d68b2a6fc
postcss-selector-parser@7.1.4
7.1.6

Open the chart page →

1,456
countlychristianhuthVerified publisher5.3.32 of 3See more

countly christianhuth 5.3.3

2 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
postcss-selector-parser@6.0.16
7.1.6
countly/frontend:25.05.42acbc11499b6
postcss-selector-parser@6.0.16
7.1.6

Open the chart page →

10,074
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
postcss-selector-parser@6.1.0
7.1.6

Open the chart page →

2,268
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

3,203
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
postcss-selector-parser@2.2.3
7.1.6

Open the chart page →

31,543
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
postcss-selector-parser@3.1.1
7.1.6

Open the chart page →

26,458
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
postcss-selector-parser@6.1.0
7.1.6
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
postcss-selector-parser@6.0.10
7.1.6
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

22,248
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

2,577
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
postcss-selector-parser@7.1.4
7.1.6

Open the chart page →

596
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

3,937
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

14,892
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

5,761
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

5,761
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss-selector-parser@6.0.13
7.1.6

Open the chart page →

5,761
codiac-cluster-agent-chartcodiac-cluster-agent1.0.381 of 1See more

codiac-cluster-agent-chart codiac-cluster-agent 1.0.38

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

1,884
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
postcss-selector-parser@5.0.0
7.1.6

Open the chart page →

15,492
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
postcss-selector-parser@6.0.10
7.1.6
coldatom/containers-security-front:latest7c2fbbb41bcf
postcss-selector-parser@6.0.10
7.1.6

Open the chart page →

11,917
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

1,824
cortezacorteza1.1.01 of 3See more

corteza corteza 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
postcss-selector-parser@7.1.0
7.1.6

Open the chart page →

9,838
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-104844.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
postcss-selector-parser@6.0.16
7.1.6

Open the chart page →

16,312

Container images carrying it

768 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
postcss-selector-parser@7.1.4
7.1.6
1
quay.io/seamware/fdsc-dashboard:0.6.63478af70bdc2
postcss-selector-parser@6.1.0
7.1.6
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
postcss-selector-parser@7.1.1
7.1.6
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
postcss-selector-parser@6.0.10
7.1.6
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
postcss-selector-parser@6.0.10
7.1.6
1
quay.io/wekan/wekan:v5.65cb17600883a3
postcss-selector-parser@3.1.2
7.1.6
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
postcss-selector-parser@7.1.1
7.1.6
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
postcss-selector-parser@6.1.2
7.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
postcss-selector-parser@7.1.1
7.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
postcss-selector-parser@7.1.1
7.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
postcss-selector-parser@7.1.1
7.1.6
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
postcss-selector-parser@7.1.1
7.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
postcss-selector-parser@7.1.4
7.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
postcss-selector-parser@7.1.4
7.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
postcss-selector-parser@7.1.4
7.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
postcss-selector-parser@7.1.4
7.1.6
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
postcss-selector-parser@7.1.1
7.1.6
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
postcss-selector-parser@6.1.0
7.1.6
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.