StackRadar

CVE-2026-45623

High

Advisory

Published 23 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
241
of 17,781 indexed, latest versions
Container images
241
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

Carried by container images the latest versions of 241 of 17,781 indexed charts deploy, on 241 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+48 more8.5.12241
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-6g55-p6wh-862qUBUNTU-CVE-2026-45623

Charts affected

241 by stars
ChartLatestAffected imagesRadar Score
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
postcss@8.5.6
8.5.12
rocketchat/authorization-service:8.6.16bc18fb5d0e5
postcss@8.5.6
8.5.12
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
postcss@8.5.6
8.5.12
rocketchat/presence-service:8.6.1c1170bdfe797
postcss@8.5.6
8.5.12

Open the chart page →

12,279
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
postcss@8.4.31
8.5.12

Open the chart page →

19,391
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
postcss@8.4.49
8.5.12

Open the chart page →

19,926
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
postcss@8.4.41
8.5.12

Open the chart page →

7,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
postcss@7.0.35
8.5.12

Open the chart page →

9,203
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
postcss@8.4.21
8.5.12

Open the chart page →

4,431
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
postcss@8.4.47
8.5.12

Open the chart page →

5,352
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
postcss@8.4.31
8.5.12

Open the chart page →

3,004
supabasetokens-studioVerified publisher1.0.01 of 14See more

supabase tokens-studio 1.0.0

1 of the 14 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
supabase/studio:20241021-9f9b08326d8070c55e9
postcss@8.4.31
8.5.12

Open the chart page →

23,123
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
postcss@8.4.31
8.5.12

Open the chart page →

2,367
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
postcss@8.4.14
8.5.12

Open the chart page →

2,581
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
postcss@8.4.31
8.5.12

Open the chart page →

17,245
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
postcss@8.4.14
8.5.12

Open the chart page →

14,238
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
postcss@8.3.11
8.5.12

Open the chart page →

5,251
klusterviewklusterviewVerified publisher0.1.01 of 4See more

klusterview klusterview 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
kyleslugg/klusterview:latestba8c36dfdfbd
postcss@8.4.24
8.5.12

Open the chart page →

3,795
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
postcss@8.4.47
8.5.12

Open the chart page →

2,654
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
postcss@8.4.49
8.5.12

Open the chart page →

7,949
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
postcss@7.0.39
8.5.12

Open the chart page →

7,450
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
postcss@8.4.32
8.5.12

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
postcss@8.4.31
8.5.12

Open the chart page →

28,839
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
postcss@8.4.40
8.5.12

Open the chart page →

3,451
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
postcss@8.4.21
8.5.12

Open the chart page →

2,521
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
postcss@7.0.36
8.5.12

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
postcss@7.0.39
8.5.12

Open the chart page →

7,579
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
postcss@8.4.13
8.5.12

Open the chart page →

10,311
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
instill/console:0.68.54cd70e2df5c6
postcss@8.5.6
8.5.12

Open the chart page →

30,816
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@6.0.22
8.5.12

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postcss@7.0.39
8.5.12

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
postcss@8.4.21
8.5.12

Open the chart page →

7,776
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
postcss@8.4.14
8.5.12

Open the chart page →

2,702
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
postcss@8.4.49
8.5.12

Open the chart page →

28,534
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
postcss@8.4.31
8.5.12

Open the chart page →

4,016
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
postcss@8.5.6
8.5.12

Open the chart page →

1,044
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
postcss@7.0.32
8.5.12

Open the chart page →

17,896
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
postcss@8.4.31
8.5.12

Open the chart page →

1,991
data-fairdata354-helmVerified publisher1.1.24 of 12See more

data-fair data354-helm 1.1.2

4 of the 12 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
postcss@8.4.31
8.5.12
ghcr.io/data-fair/metrics:0a8d40779eeae
postcss@7.0.39
8.5.12
ghcr.io/data-fair/notify:3c739b74dabb0
postcss@8.5.3
8.5.12
ghcr.io/data-fair/processings:15a9216989707
postcss@8.4.31
8.5.12

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
8.5.12

Open the chart page →

5,056
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
postcss@8.4.31
8.5.12

Open the chart page →

3,925
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
postcss@8.5.6
8.5.12

Open the chart page →

1,442
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
postcss@8.4.6
8.5.12

Open the chart page →

4,260
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
postcss@8.2.13
8.5.12

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
postcss@7.0.39
8.5.12

Open the chart page →

7,801
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
postcss@8.4.14
8.5.12

Open the chart page →

5,079
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
postcss@8.5.6
8.5.12

Open the chart page →

15,712
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
postcss@8.5.1
8.5.12

Open the chart page →

5,228
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
postcss@8.4.31
8.5.12

Open the chart page →

2,770
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
postcss@7.0.39
8.5.12

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
postcss@8.4.31
8.5.12

Open the chart page →

20,403
bulwark-maill4gVerified publisher0.2.21 of 1See more

bulwark-mail l4g 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/bulwarkmail/webmail:1.6.0f0a266506fcf
postcss@8.4.31
8.5.12

Open the chart page →

800
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
chibisafe/chibisafe:latest836467a50792
postcss@8.4.31
8.5.12
chibisafe/chibisafe-server:latest3da4fcbc1a18
postcss@8.4.37
8.5.12

Open the chart page →

5,654

Container images carrying it

241 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
postcss@8.4.31
8.5.12
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
postcss@8.4.31
8.5.12
1
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
postcss@8.4.31
8.5.12
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
postcss@8.4.31
8.5.12
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
postcss@8.5.10
8.5.12
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
postcss@8.5.10
8.5.12
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
postcss@8.4.31
8.5.12
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
postcss@8.4.47
8.5.12
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
postcss@6.0.23
8.5.12
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
8.5.12
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
postcss@8.4.14
8.5.12
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
postcss@8.4.31
8.5.12
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
postcss@8.4.38
8.5.12
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
postcss@8.4.31
8.5.12
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
postcss@8.4.49
8.5.12
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
postcss@8.4.31
8.5.12
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
postcss@8.5.1
8.5.12
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
postcss@7.0.32
8.5.12
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
postcss@8.5.6
8.5.12
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
postcss@8.2.13
8.5.12
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
postcss@8.4.14
8.5.12
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
postcss@7.0.39
8.5.12
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
postcss@8.4.31
8.5.12
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
postcss@8.4.49
8.5.12
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
postcss@8.4.31
8.5.12
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
postcss@8.4.31
8.5.12
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
postcss@8.4.31
8.5.12
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
postcss@8.4.31
8.5.12
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
postcss@8.4.31
8.5.12
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
postcss@8.4.21
8.5.12
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
postcss@8.5.6
8.5.12
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
postcss@8.5.6
8.5.12
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
postcss@8.5.6
8.5.12
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
postcss@8.4.31
8.5.12
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
postcss@8.4.31
8.5.12
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
postcss@7.0.38
8.5.12
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
postcss@7.0.17
8.5.12
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
postcss@8.4.31
8.5.12
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postcss@7.0.21
8.5.12
1
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
8.5.12
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
postcss@8.4.31
8.5.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.