StackRadar

CVE-2026-41305

Medium

Advisory

Published 24 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
238
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 238 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+47 more8.5.10238
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-qx2v-qp2m-jg93UBUNTU-CVE-2026-41305

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
8.5.10

Open the chart page →

5,940
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
postcss@8.5.8
8.5.10

Open the chart page →

2,575
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
postcss@8.5.6
8.5.10

Open the chart page →

6,873
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
postcss@8.5.6
8.5.10

Open the chart page →

7,035
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
postcss@8.4.31
8.5.10

Open the chart page →

31,844
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
postcss@8.4.31
8.5.10

Open the chart page →

2,823
kyoorubxkubeVerified publisher0.1.101 of 9See more

kyoo rubxkube 0.1.10

1 of the 9 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
postcss@8.4.31
8.5.10

Open the chart page →

30,234
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
postcss@8.4.31
8.5.10

Open the chart page →

5,213
vuiseriohub1.0.61 of 3See more

vui seriohub 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
dserio83/velero-ui:0.3.1b4e1ec6664d3
postcss@8.4.31
8.5.10

Open the chart page →

11,532
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
speckle/speckle-server:2.26.379f14a2bf931
postcss@8.5.6
8.5.10

Open the chart page →

10,380
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
postcss@7.0.27
8.5.10

Open the chart page →

7,517
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
postcss@7.0.39
8.5.10

Open the chart page →

12,581
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
postcss@8.4.31
8.5.10

Open the chart page →

5,225
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
postcss@8.4.31
8.5.10

Open the chart page →

10,090
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
postcss@8.5.6
8.5.10
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
postcss@8.5.8
8.5.10

Open the chart page →

3,600
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
postcss@8.4.31
8.5.10

Open the chart page →

3,820
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
postcss@8.4.31
8.5.10

Open the chart page →

4,497
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
8.5.10

Open the chart page →

3,237
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
postcss@7.0.39
8.5.10

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
postcss@8.4.14
8.5.10

Open the chart page →

2,396
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0b6a67099e4c5
postcss@8.5.6
8.5.10

Open the chart page →

4,923
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
postcss@8.4.21
8.5.10

Open the chart page →

18,277
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
postcss@8.4.35
8.5.10

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
postcss@8.3.5
8.5.10

Open the chart page →

7,152
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
postcss@8.4.14
8.5.10

Open the chart page →

3,071
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
postcss@4.1.16
8.5.10

Open the chart page →

4,069
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
postcss@8.4.38
8.5.10

Open the chart page →

1,306
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
postcss@8.4.47
8.5.10

Open the chart page →

14,130
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
postcss@8.5.6
8.5.10

Open the chart page →

4,083
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
postcss@8.4.31
8.5.10

Open the chart page →

1,977
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
postcss@8.4.31
8.5.10

Open the chart page →

2,759
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
postcss@5.2.18
8.5.10

Open the chart page →

29,901
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
postcss@7.0.17
8.5.10

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
postcss@8.4.49
8.5.10
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
postcss@8.5.6
8.5.10
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
postcss@8.5.6
8.5.10

Open the chart page →

18,293
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-postcss@8.4.31+~cs8.0.26-1
postcss@8.4.31
no fix listed
8.5.10

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss@8.4.31
8.5.10

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss@8.4.31
8.5.10

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
postcss@8.4.31
8.5.10

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
postcss@7.0.35
8.5.10

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
postcss@7.0.39
8.5.10

Open the chart page →

9,146
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
postcss@8.5.8
8.5.10

Open the chart page →

1,527
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
postcss@8.4.31
8.5.10

Open the chart page →

551
homarrdelerVerified publisher1.0.11 of 1See more

homarr deler 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
postcss@8.4.14
8.5.10

Open the chart page →

1,924
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
postcss@8.5.1
8.5.10

Open the chart page →

2,529
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
postcss@8.4.31
8.5.10

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
postcss@8.4.41
8.5.10

Open the chart page →

4,551
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
postcss@8.4.31
8.5.10

Open the chart page →

2,862
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
postcss@8.4.47
8.5.10

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
postcss@7.0.23
8.5.10

Open the chart page →

11,174
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
postcss@8.4.31
8.5.10

Open the chart page →

1,344

Container images carrying it

238 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
drumsergio/lynxprompt:2.0.75c6afb6679301
postcss@8.4.31
8.5.10
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
postcss@8.4.31
8.5.10
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
postcss@8.4.14
8.5.10
1
ethersphere/onboarding-faucet:0.3.0513154aab230
postcss@8.4.5
8.5.10
1
ethpandaops/blobscan:latest7a9ab6370657
postcss@8.4.14
8.5.10
1
ethpandaops/ethereumjs:masterfb84b718500f
postcss@8.5.6
8.5.10
1
factly/mande-web:0.34.1742355964b0e
postcss@8.4.14
8.5.10
1
fallenbagel/jellyseerr:latest4538137bc5af
postcss@8.4.31
8.5.10
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
postcss@8.4.14
8.5.10
1
felipecs8/conversor-temperatura:v1f945423be36d
postcss@8.5.8
8.5.10
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@6.0.22
8.5.10
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
postcss@8.4.31
8.5.10
1
fosrl/pangolin:1.13.0c32ad797ab96
postcss@8.4.31
8.5.10
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
postcss@7.0.39
8.5.10
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.5.10
1
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.5.10
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
postcss@7.0.39
8.5.10
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
postcss@8.5.3
8.5.10
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
postcss@8.4.47
8.5.10
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
8.5.10
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
postcss@6.0.23
8.5.10
1
ibmcom/microclimate-portal:latested5505e5c7ec
postcss@6.0.17
8.5.10
1
instill/console:0.68.54cd70e2df5c6
postcss@8.5.6
8.5.10
1
jayfong/yapi:1.10.2163e5d621910
postcss@5.2.18
8.5.10
1
joplin/server:3.0-beta52af57880c0e
postcss@8.4.24
8.5.10
1
joplin/server:2.14.2-betab87564ef34e9
postcss@8.4.31
8.5.10
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-postcss@8.4.31+~cs8.0.26-1
postcss@8.4.31
no fix listed
8.5.10
1
keyoxide/keyoxide:stable96f27a71269d
postcss@8.4.11
8.5.10
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postcss@7.0.39
8.5.10
1
konradkleine/docker-registry-frontend:v2181aad54ee64
postcss@4.1.16
8.5.10
1
kyleslugg/klusterview:latestba8c36dfdfbd
postcss@8.4.24
8.5.10
1
kyso/kyso-front:lateste52595c5c16f
postcss@8.4.30
8.5.10
1
langgenius/dify-web:0.6.11a2a294743634
postcss@8.4.31
8.5.10
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
postcss@8.4.31
8.5.10
1
langgenius/dify-web:1.0.0d64914ff0d6d
postcss@8.4.31
8.5.10
1
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
8.5.10
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@8.4.38
8.5.10
1
library/ghost:6.37.01ef2e532ca4d
postcss@8.5.6
8.5.10
1
library/ghost:6.25.12654b1e90413
postcss@8.5.6
8.5.10
1
library/ghost:6.41.129773d6be407
postcss@8.5.6
8.5.10
1
library/ghost:4.37.0767230c0f263
postcss@8.4.6
8.5.10
1
library/ghost:6.39.0-alpine77196da4b0df
postcss@8.5.6
8.5.10
1
library/ghost:5.79.083f7bf209844
postcss@8.4.33
8.5.10
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
postcss@8.5.6
8.5.10
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
postcss@7.0.36
8.5.10
1
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
8.5.10
1
linuxserver/overseerr:1.35.06108ed066d4a
postcss@8.4.14
8.5.10
1
lissy93/dashy:2.0.51991f7be5ed0
postcss@7.0.39
8.5.10
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
postcss@8.4.31
8.5.10
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
postcss@8.4.14
8.5.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.