StackRadar

CVE-2026-45623

High

Advisory

Published 23 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
241
of 17,781 indexed, latest versions
Container images
241
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

Carried by container images the latest versions of 241 of 17,781 indexed charts deploy, on 241 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+48 more8.5.12241
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-6g55-p6wh-862qUBUNTU-CVE-2026-45623

Charts affected

241 by stars
ChartLatestAffected imagesRadar Score
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
postcss@8.4.31
8.5.12

Open the chart page →

5,338
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
postcss@8.4.24
8.5.12

Open the chart page →

7,413
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
postcss@8.5.6
8.5.12

Open the chart page →

5,819
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
postcss@8.5.6
8.5.12

Open the chart page →

4,684
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.5.12

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
8.5.12

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@8.4.38
8.5.12

Open the chart page →

5,497
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
postcss@8.4.31
8.5.12

Open the chart page →

1,991
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.5.12

Open the chart page →

3,143
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
postcss@8.4.14
8.5.12

Open the chart page →

4,820
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
postcss@7.0.21
8.5.12

Open the chart page →

3,696
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.5.12

Open the chart page →

7,574
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.5.12

Open the chart page →

2,460
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
postcss@8.4.31
8.5.12

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
postcss@8.4.31
8.5.12

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
postcss@8.4.31
8.5.12

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
postcss@8.4.31
8.5.12

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
postcss@8.4.31
8.5.12

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
postcss@8.4.31
8.5.12

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
postcss@8.4.31
8.5.12

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
postcss@8.4.31
8.5.12

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
postcss@8.4.31
8.5.12

Open the chart page →

11,100
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.5.12

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
postcss@8.3.0
8.5.12

Open the chart page →

11,554
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
postcss@8.4.39
8.5.12

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
postcss@6.0.23
8.5.12

Open the chart page →

3,881
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
postcss@8.5.3
8.5.12

Open the chart page →

1,653
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
postcss@8.4.6
8.5.12

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
postcss@8.5.10
8.5.12

Open the chart page →

3,972
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
postcss@8.4.47
8.5.12

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
postcss@8.4.47
8.5.12

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
postcss@8.4.47
8.5.12

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
postcss@7.0.39
8.5.12

Open the chart page →

20,270
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
postcss@7.0.35
8.5.12

Open the chart page →

4,661
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
postcss@8.4.31
8.5.12
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
postcss@8.4.31
8.5.12
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
postcss@8.4.31
8.5.12

Open the chart page →

6,994
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
postcss@8.5.1
8.5.12

Open the chart page →

5,228
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
postcss@8.4.31
8.5.12

Open the chart page →

2,789
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
postcss@8.4.31
8.5.12

Open the chart page →

5,984
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
postcss@6.0.23
8.5.12

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.5.12

Open the chart page →

22,665
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
postcss@8.4.31
8.5.12
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
postcss@8.4.31
8.5.12
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
postcss@8.4.31
8.5.12

Open the chart page →

16,083

Container images carrying it

241 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.5.12
1
tensorzero/ui:2026.6.0f2563d54724e
postcss@8.5.10
8.5.12
1
testhubio/testhub-frontend:on-preme86c2db53be8
postcss@7.0.27
8.5.12
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
postcss@8.4.31
8.5.12
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
postcss@8.4.31
8.5.12
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
postcss@8.4.31
8.5.12
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
postcss@8.4.49
8.5.12
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
postcss@8.4.12
8.5.12
1
treskon/portrait-ui:DEV-lateste7970783bc8d
postcss@8.4.31
8.5.12
1
ubercadence/web:v3.29.58564a5b44a6d
postcss@6.0.23
8.5.12
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
postcss@8.4.41
8.5.12
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
postcss@7.0.39
8.5.12
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
postcss@8.4.31
8.5.12
1
vlebediantsev/notes-admin-front:latest007c6670ff48
postcss@8.4.27
8.5.12
1
vlebediantsev/notes-project-front:latest945675fd2636
postcss@7.0.39
8.5.12
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
postcss@7.0.39
8.5.12
1
winfred008/amazon:910a68de5b398
postcss@8.4.23
8.5.12
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
postcss@8.4.31
8.5.12
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
postcss@8.4.31
8.5.12
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
postcss@8.4.14
8.5.12
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
postcss@8.4.14
8.5.12
1
ghcr.io/ajnart/homarr:lateste103abadfb52
postcss@8.4.31
8.5.12
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
postcss@8.4.31
8.5.12
1
ghcr.io/argonix-io/argonix-api-frontend:1.0.0b6a67099e4c5
postcss@8.5.6
8.5.12
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
postcss@8.5.8
8.5.12
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
postcss@8.4.35
8.5.12
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
postcss@8.4.38
8.5.12
1
ghcr.io/bulwarkmail/webmail:1.6.0f0a266506fcf
postcss@8.4.31
8.5.12
1
ghcr.io/caninehq/canine:latesta058034ca006
postcss@8.4.47
8.5.12
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
postcss@8.4.31
8.5.12
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
postcss@7.0.32
8.5.12
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
postcss@7.0.32
8.5.12
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
postcss@7.0.32
8.5.12
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
postcss@7.0.32
8.5.12
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
postcss@8.5.3
8.5.12
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
postcss@8.4.47
8.5.12
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
postcss@8.4.31
8.5.12
1
ghcr.io/data-fair/metrics:0a8d40779eeae
postcss@7.0.39
8.5.12
1
ghcr.io/data-fair/notify:3c739b74dabb0
postcss@8.5.3
8.5.12
1
ghcr.io/data-fair/processings:15a9216989707
postcss@8.4.31
8.5.12
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
postcss@8.4.31
8.5.12
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
postcss@8.4.49
8.5.12
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
postcss@8.5.6
8.5.12
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
postcss@8.5.6
8.5.12
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
postcss@8.4.31
8.5.12
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
postcss@8.4.31
8.5.12
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
postcss@7.0.39
8.5.12
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
postcss@8.5.1
8.5.12
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postcss@8.5.6
8.5.12
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
postcss@8.4.31
8.5.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.