StackRadar

CVE-2026-41305

Medium

Advisory

Published 24 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
238
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 238 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+47 more8.5.10238
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-qx2v-qp2m-jg93UBUNTU-CVE-2026-41305

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
postcss@8.5.6
8.5.10
rocketchat/authorization-service:8.6.16bc18fb5d0e5
postcss@8.5.6
8.5.10
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
postcss@8.5.6
8.5.10
rocketchat/presence-service:8.6.1c1170bdfe797
postcss@8.5.6
8.5.10

Open the chart page →

12,279
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
postcss@8.4.31
8.5.10

Open the chart page →

19,391
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
postcss@8.4.49
8.5.10

Open the chart page →

19,926
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
postcss@8.4.41
8.5.10

Open the chart page →

7,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
8.5.10

Open the chart page →

9,203
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.5.10

Open the chart page →

4,431
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
postcss@8.4.47
8.5.10

Open the chart page →

5,352
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
postcss@8.4.31
8.5.10

Open the chart page →

3,004
supabasetokens-studioVerified publisher1.0.01 of 14See more

supabase tokens-studio 1.0.0

1 of the 14 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
supabase/studio:20241021-9f9b08326d8070c55e9
postcss@8.4.31
8.5.10

Open the chart page →

23,123
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
postcss@8.4.31
8.5.10

Open the chart page →

2,367
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
postcss@8.4.14
8.5.10

Open the chart page →

2,581
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
postcss@8.4.31
8.5.10

Open the chart page →

17,245
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
postcss@8.4.14
8.5.10

Open the chart page →

14,238
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
postcss@8.3.11
8.5.10

Open the chart page →

5,251
klusterviewklusterviewVerified publisher0.1.01 of 4See more

klusterview klusterview 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
kyleslugg/klusterview:latestba8c36dfdfbd
postcss@8.4.24
8.5.10

Open the chart page →

3,795
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
postcss@8.4.47
8.5.10

Open the chart page →

2,654
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
postcss@8.4.49
8.5.10

Open the chart page →

7,949
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
postcss@7.0.39
8.5.10

Open the chart page →

7,450
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
postcss@8.4.32
8.5.10

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
postcss@8.4.31
8.5.10

Open the chart page →

28,839
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
postcss@8.4.40
8.5.10

Open the chart page →

3,451
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
postcss@8.4.21
8.5.10

Open the chart page →

2,521
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
postcss@7.0.36
8.5.10

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
postcss@7.0.39
8.5.10

Open the chart page →

7,579
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.10

Open the chart page →

10,311
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
instill/console:0.68.54cd70e2df5c6
postcss@8.5.6
8.5.10

Open the chart page →

30,816
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@6.0.22
8.5.10

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postcss@7.0.39
8.5.10

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
postcss@8.4.21
8.5.10

Open the chart page →

7,776
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
postcss@8.4.14
8.5.10

Open the chart page →

2,702
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
postcss@8.4.49
8.5.10

Open the chart page →

28,534
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
postcss@8.4.31
8.5.10

Open the chart page →

4,016
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
postcss@8.5.6
8.5.10

Open the chart page →

1,044
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
8.5.10

Open the chart page →

17,896
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
postcss@8.4.31
8.5.10

Open the chart page →

1,991
data-fairdata354-helmVerified publisher1.1.24 of 12See more

data-fair data354-helm 1.1.2

4 of the 12 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
postcss@8.4.31
8.5.10
ghcr.io/data-fair/metrics:0a8d40779eeae
postcss@7.0.39
8.5.10
ghcr.io/data-fair/notify:3c739b74dabb0
postcss@8.5.3
8.5.10
ghcr.io/data-fair/processings:15a9216989707
postcss@8.4.31
8.5.10

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
8.5.10

Open the chart page →

5,056
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
postcss@8.4.31
8.5.10

Open the chart page →

3,925
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
postcss@8.5.6
8.5.10

Open the chart page →

1,442
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
postcss@8.4.6
8.5.10

Open the chart page →

4,260
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
postcss@8.2.13
8.5.10

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
postcss@7.0.39
8.5.10

Open the chart page →

7,801
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
postcss@8.4.14
8.5.10

Open the chart page →

5,079
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postcss@8.5.6
8.5.10

Open the chart page →

15,712
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
postcss@8.5.1
8.5.10

Open the chart page →

5,228
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
postcss@8.4.31
8.5.10

Open the chart page →

2,770
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.5.10

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
postcss@8.4.31
8.5.10

Open the chart page →

20,403
bulwark-maill4gVerified publisher0.2.21 of 1See more

bulwark-mail l4g 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/bulwarkmail/webmail:1.6.0f0a266506fcf
postcss@8.4.31
8.5.10

Open the chart page →

800
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
chibisafe/chibisafe:latest836467a50792
postcss@8.4.31
8.5.10
chibisafe/chibisafe-server:latest3da4fcbc1a18
postcss@8.4.37
8.5.10

Open the chart page →

5,654

Container images carrying it

238 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.5.10
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss@8.4.31
8.5.10
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.10
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
postcss@8.4.31
8.5.10
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
8.5.10
2
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
8.5.10
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
postcss@8.4.40
8.5.10
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
postcss@7.0.36
8.5.10
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
8.5.10
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
postcss@7.0.39
8.5.10
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
postcss@7.0.39
8.5.10
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
postcss@7.0.39
8.5.10
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
postcss@8.5.6
8.5.10
2
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.5.10
2
rajnandan1/kener:3.2.1930407afca731
postcss@8.5.1
8.5.10
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.5.10
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
postcss@8.4.31
8.5.10
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.5.10
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
postcss@8.4.31
8.5.10
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
postcss@8.5.6
8.5.10
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
postcss@8.5.8
8.5.10
1
alquimiaai/studio:certification38a1f0341982
postcss@8.4.31
8.5.10
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
8.5.10
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
8.5.10
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
postcss@8.4.45
8.5.10
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
postcss@8.4.31
8.5.10
1
apimap/developer:v1.3.1406d3858e20c
postcss@7.0.39
8.5.10
1
apimap/portal:v2.4.0041a4790c65c
postcss@8.4.14
8.5.10
1
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.36
8.5.10
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
8.5.10
1
assistiot/open_api_frontend:1.0.1f11d82defc70
postcss@8.4.21
8.5.10
1
automatischio/automatisch:0.15.03bace7a12d5f
postcss@8.5.3
8.5.10
1
baserow/baserow:1.30.1df0c42eb67e8
postcss@8.4.32
8.5.10
1
ccjacobs14/amazon:59a9b14a6f09e
postcss@8.4.23
8.5.10
1
chainsafe/lodestar:latest5593f6e97912
postcss@8.5.6
8.5.10
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
postcss@8.4.39
8.5.10
1
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
8.5.10
1
chibisafe/chibisafe:latest836467a50792
postcss@8.4.31
8.5.10
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
postcss@8.4.37
8.5.10
1
chocobozzz/peertube:v8.1.5052712130691
postcss@8.5.6
8.5.10
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postcss@6.0.23
8.5.10
1
codetogether/codetogether:latest4348c8a38752
postcss@7.0.39
8.5.10
1
coldatom/containers-security-front:latest7c2fbbb41bcf
postcss@7.0.39
8.5.10
1
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
8.5.10
1
daskdev/dask-notebook:1.1.0052630f5ca04
postcss@5.2.18
8.5.10
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
postcss@8.4.41
8.5.10
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
postcss@8.4.31
8.5.10
1
directus/directus:11.1.0e3c8bb975350
postcss@8.4.41
8.5.10
1
diygod/rsshub:2025-11-097a6312cac0d5
postcss@8.5.6
8.5.10
1
documenso/documenso:v1.8.17f16a9449f18
postcss@8.4.31
8.5.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.