StackRadar

CVE-2026-41305

Medium

Advisory

Published 24 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
238
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 238 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+47 more8.5.10238
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-qx2v-qp2m-jg93UBUNTU-CVE-2026-41305

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
postcss@7.0.36
8.5.10

Open the chart page →

3,744
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
postcss@8.4.14
8.5.10

Open the chart page →

1,329
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
postcss@8.5.6
8.5.10

Open the chart page →

2,522
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
postcss@7.0.14
8.5.10

Open the chart page →

3,005
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
postcss@8.4.5
8.5.10

Open the chart page →

3,320
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
postcss@8.4.14
8.5.10

Open the chart page →

4,777
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
postcss@8.4.31
8.5.10

Open the chart page →

4,650
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
postcss@8.2.4
8.5.10

Open the chart page →

4,043
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
postcss@8.4.33
8.5.10

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
8.5.10

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
postcss@7.0.35
8.5.10

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.82 of 27See more

opentelemetry-demo gpg-dev 0.33.8

2 of the 27 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
postcss@8.4.38
8.5.10
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
postcss@8.4.31
8.5.10

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.10

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.10

Open the chart page →

2,682
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
postcss@8.5.3
8.5.10

Open the chart page →

2,950
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
postcss@7.0.32
8.5.10
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
postcss@7.0.32
8.5.10
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
postcss@7.0.32
8.5.10
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
postcss@7.0.32
8.5.10

Open the chart page →

89,959
lobe-chathelm-charts-darox0.1.561 of 1See more

lobe-chat helm-charts-darox 0.1.56

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
lobehub/lobe-chat:1.96.9da0c21fefcd3
postcss@8.4.31
8.5.10

Open the chart page →

666
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
postcss@8.4.40
8.5.10

Open the chart page →

3,451
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
postcss@8.5.3
8.5.10

Open the chart page →

5,769
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
postcss@8.4.49
8.5.10

Open the chart page →

2,538
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
postcss@8.5.1
8.5.10

Open the chart page →

6,012
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
postcss@8.4.16
8.5.10

Open the chart page →

25,017
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
postcss@8.4.31
8.5.10

Open the chart page →

1,468
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
postcss@8.4.47
8.5.10

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
postcss@7.0.39
8.5.10

Open the chart page →

3,407
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
postcss@6.0.23
8.5.10

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
postcss@6.0.17
8.5.10

Open the chart page →

57,669
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
postcss@8.4.41
8.5.10

Open the chart page →

11,812
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
postcss@8.4.14
8.5.10

Open the chart page →

4,944
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
postcss@8.4.11
8.5.10

Open the chart page →

2,363
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
postcss@8.5.6
8.5.10

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
postcss@8.5.3
8.5.10

Open the chart page →

5,826
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
postcss@5.2.18
8.5.10

Open the chart page →

6,454
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
postcss@8.5.6
8.5.10

Open the chart page →

3,092
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
postcss@8.5.1
8.5.10

Open the chart page →

5,228
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
postcss@8.4.5
8.5.10

Open the chart page →

4,230
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
postcss@8.4.31
8.5.10

Open the chart page →

3,441
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
postcss@8.4.12
8.5.10

Open the chart page →

5,410
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
postcss@8.4.31
8.5.10

Open the chart page →

8,405
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
postcss@8.5.6
8.5.10

Open the chart page →

2,756
homepagekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

homepage kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
postcss@8.4.31
8.5.10

Open the chart page →

1,378
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
postcss@8.4.31
8.5.10

Open the chart page →

1,498
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
postcss@8.4.31
8.5.10

Open the chart page →

2,548
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
postcss@8.4.30
8.5.10

Open the chart page →

2,685
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
postcss@8.4.31
8.5.10

Open the chart page →

3,555
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
postcss@8.4.31
8.5.10

Open the chart page →

1,344
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
postcss@7.0.17
8.5.10

Open the chart page →

7,929
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
postcss@8.2.13
8.5.10

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
8.5.10

Open the chart page →

3,651
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41305.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
postcss@8.4.31
8.5.10

Open the chart page →

1,852

Container images carrying it

238 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
drumsergio/lynxprompt:2.0.75c6afb6679301
postcss@8.4.31
8.5.10
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
postcss@8.4.31
8.5.10
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
postcss@8.4.14
8.5.10
1
ethersphere/onboarding-faucet:0.3.0513154aab230
postcss@8.4.5
8.5.10
1
ethpandaops/blobscan:latest7a9ab6370657
postcss@8.4.14
8.5.10
1
ethpandaops/ethereumjs:masterfb84b718500f
postcss@8.5.6
8.5.10
1
factly/mande-web:0.34.1742355964b0e
postcss@8.4.14
8.5.10
1
fallenbagel/jellyseerr:latest4538137bc5af
postcss@8.4.31
8.5.10
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
postcss@8.4.14
8.5.10
1
felipecs8/conversor-temperatura:v1f945423be36d
postcss@8.5.8
8.5.10
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@6.0.22
8.5.10
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
postcss@8.4.31
8.5.10
1
fosrl/pangolin:1.13.0c32ad797ab96
postcss@8.4.31
8.5.10
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
postcss@7.0.39
8.5.10
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.5.10
1
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.5.10
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
postcss@7.0.39
8.5.10
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
postcss@8.5.3
8.5.10
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
postcss@8.4.47
8.5.10
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
8.5.10
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
postcss@6.0.23
8.5.10
1
ibmcom/microclimate-portal:latested5505e5c7ec
postcss@6.0.17
8.5.10
1
instill/console:0.68.54cd70e2df5c6
postcss@8.5.6
8.5.10
1
jayfong/yapi:1.10.2163e5d621910
postcss@5.2.18
8.5.10
1
joplin/server:3.0-beta52af57880c0e
postcss@8.4.24
8.5.10
1
joplin/server:2.14.2-betab87564ef34e9
postcss@8.4.31
8.5.10
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-postcss@8.4.31+~cs8.0.26-1
postcss@8.4.31
no fix listed
8.5.10
1
keyoxide/keyoxide:stable96f27a71269d
postcss@8.4.11
8.5.10
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postcss@7.0.39
8.5.10
1
konradkleine/docker-registry-frontend:v2181aad54ee64
postcss@4.1.16
8.5.10
1
kyleslugg/klusterview:latestba8c36dfdfbd
postcss@8.4.24
8.5.10
1
kyso/kyso-front:lateste52595c5c16f
postcss@8.4.30
8.5.10
1
langgenius/dify-web:0.6.11a2a294743634
postcss@8.4.31
8.5.10
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
postcss@8.4.31
8.5.10
1
langgenius/dify-web:1.0.0d64914ff0d6d
postcss@8.4.31
8.5.10
1
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
8.5.10
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@8.4.38
8.5.10
1
library/ghost:6.37.01ef2e532ca4d
postcss@8.5.6
8.5.10
1
library/ghost:6.25.12654b1e90413
postcss@8.5.6
8.5.10
1
library/ghost:6.41.129773d6be407
postcss@8.5.6
8.5.10
1
library/ghost:4.37.0767230c0f263
postcss@8.4.6
8.5.10
1
library/ghost:6.39.0-alpine77196da4b0df
postcss@8.5.6
8.5.10
1
library/ghost:5.79.083f7bf209844
postcss@8.4.33
8.5.10
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
postcss@8.5.6
8.5.10
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
postcss@7.0.36
8.5.10
1
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
8.5.10
1
linuxserver/overseerr:1.35.06108ed066d4a
postcss@8.4.14
8.5.10
1
lissy93/dashy:2.0.51991f7be5ed0
postcss@7.0.39
8.5.10
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
postcss@8.4.31
8.5.10
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
postcss@8.4.14
8.5.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.