StackRadar

CVE-2026-45623

High

Advisory

Published 23 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
241
of 17,781 indexed, latest versions
Container images
241
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

Carried by container images the latest versions of 241 of 17,781 indexed charts deploy, on 241 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+48 more8.5.12241
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-6g55-p6wh-862qUBUNTU-CVE-2026-45623

Charts affected

241 by stars
ChartLatestAffected imagesRadar Score
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
postcss@8.4.31
8.5.12

Open the chart page →

1,852
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
postcss@8.4.31
8.5.12

Open the chart page →

4,647
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
postcss@8.4.31
8.5.12

Open the chart page →

24,400
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
postcss@6.0.23
8.5.12

Open the chart page →

5,287
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
postcss@8.5.6
8.5.12

Open the chart page →

8,303
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
postcss@7.0.35
8.5.12

Open the chart page →

5,940
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.5.12

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.5.12

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
postcss@7.0.36
8.5.12

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
postcss@8.5.6
8.5.12

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
postcss@7.0.39
8.5.12
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
postcss@7.0.39
8.5.12
mojaloop/role-assignment-service:v2.1.0def4bf273721
postcss@7.0.39
8.5.12

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
8.5.12

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
postcss@7.0.36
8.5.12
mojaloop/central-ledger:v13.14.01abc8a7aa71c
postcss@7.0.36
8.5.12
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
postcss@7.0.35
8.5.12

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
postcss@7.0.39
8.5.12

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
postcss@7.0.39
8.5.12

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
postcss@7.0.39
8.5.12

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
postcss@8.5.6
8.5.12

Open the chart page →

2,457
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postcss@7.0.21
8.5.12

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
postcss@7.0.25
8.5.12

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
postcss@8.4.33
8.5.12

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
postcss@8.5.6
8.5.12

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
postcss@8.4.21
8.5.12

Open the chart page →

6,608
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
postcss@8.4.31
8.5.12

Open the chart page →

4,016
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
postcss@6.0.23
8.5.12

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
postcss@8.4.23
8.5.12

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
postcss@8.4.23
8.5.12

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
postcss@7.0.39
8.5.12

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
postcss@8.4.23
8.5.12

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
postcss@7.0.39
8.5.12

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
postcss@7.0.39
8.5.12

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
postcss@6.0.23
8.5.12

Open the chart page →

109,294
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
postcss@8.4.31
8.5.12

Open the chart page →

7,184
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
postcss@8.4.31
8.5.12

Open the chart page →

1,569
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
postcss@8.5.8
8.5.12

Open the chart page →

3,798
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
postcss@8.4.21
8.5.12

Open the chart page →

2,919
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
postcss@8.4.27
8.5.12

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
postcss@7.0.39
8.5.12

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
postcss@7.0.39
8.5.12

Open the chart page →

15,187
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
8.5.12

Open the chart page →

27,465
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit:1.24.02434560e8f0e
postcss@8.4.31
8.5.12

Open the chart page →

5,017
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
postcss@8.4.31
8.5.12

Open the chart page →

2,370
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
postcss@7.0.38
8.5.12

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
postcss@6.0.23
8.5.12

Open the chart page →

6,524
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
postcss@8.4.31
8.5.12

Open the chart page →

2,969
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
postcss@8.4.31
8.5.12

Open the chart page →

1,506
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
postcss@8.4.45
8.5.12

Open the chart page →

3,271
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
postcss@8.5.3
8.5.12

Open the chart page →

4,763
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
postcss@8.4.31
8.5.12

Open the chart page →

7,084
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
postcss@8.5.6
8.5.12

Open the chart page →

4,600
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-45623.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
postcss@7.0.32
8.5.12

Open the chart page →

6,026

Container images carrying it

241 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
postcss@8.4.31
8.5.12
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
postcss@8.4.31
8.5.12
1
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
postcss@8.4.31
8.5.12
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
postcss@8.4.31
8.5.12
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
postcss@8.5.10
8.5.12
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
postcss@8.5.10
8.5.12
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
postcss@8.4.31
8.5.12
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
postcss@8.4.47
8.5.12
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
postcss@6.0.23
8.5.12
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
postcss@7.0.32
8.5.12
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
postcss@8.4.14
8.5.12
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
postcss@8.4.31
8.5.12
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
postcss@8.4.38
8.5.12
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
postcss@8.4.31
8.5.12
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
postcss@8.4.49
8.5.12
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
postcss@8.4.31
8.5.12
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
postcss@8.5.1
8.5.12
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
postcss@7.0.32
8.5.12
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
postcss@8.5.6
8.5.12
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
postcss@8.2.13
8.5.12
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
postcss@8.4.14
8.5.12
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
postcss@7.0.39
8.5.12
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
postcss@8.4.31
8.5.12
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
postcss@8.4.49
8.5.12
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
postcss@8.4.31
8.5.12
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
postcss@8.4.31
8.5.12
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
postcss@8.4.31
8.5.12
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
postcss@8.4.31
8.5.12
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
postcss@8.4.31
8.5.12
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
postcss@8.4.21
8.5.12
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
postcss@8.5.6
8.5.12
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
postcss@8.5.6
8.5.12
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
postcss@8.5.6
8.5.12
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
postcss@8.4.31
8.5.12
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
postcss@8.4.31
8.5.12
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
postcss@7.0.38
8.5.12
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
postcss@7.0.17
8.5.12
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
postcss@8.4.31
8.5.12
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
postcss@7.0.21
8.5.12
1
quay.io/wekan/wekan:v5.65cb17600883a3
postcss@7.0.35
8.5.12
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
postcss@8.4.31
8.5.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.