StackRadar

CVE-2026-69153

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
252
of 17,781 indexed, latest versions
Container images
253
deployed by those charts
Fix available
1 of 2
affected packages

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

Carried by container images the latest versions of 252 of 17,781 indexed charts deploy, on 253 images.

Affected packageAffected versionsFixed inImages
postcssnpm4.1.16, 5.2.18, 6.0.17, 6.0.22+53 more8.5.23253
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-fxqj-rqcc-2cmpUBUNTU-CVE-2026-69153

Charts affected

252 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
postcss@6.0.23
8.5.23

Open the chart page →

22,665
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-69153.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
postcss@8.4.31
8.5.23
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
postcss@8.4.31
8.5.23
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
postcss@8.4.31
8.5.23

Open the chart page →

16,083

Container images carrying it

253 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
diygod/rsshub:2025-11-097a6312cac0d5
postcss@8.5.6
8.5.23
1
documenso/documenso:v1.8.17f16a9449f18
postcss@8.4.31
8.5.23
1
drumsergio/lynxprompt:2.0.75c6afb6679301
postcss@8.5.14
8.5.23
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
postcss@8.4.31
8.5.23
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
postcss@8.4.14
8.5.23
1
ethersphere/onboarding-faucet:0.3.0513154aab230
postcss@8.4.5
8.5.23
1
ethpandaops/blobscan:latest7a9ab6370657
postcss@8.4.14
8.5.23
1
ethpandaops/ethereumjs:masterfb84b718500f
postcss@8.5.6
8.5.23
1
factly/mande-web:0.34.1742355964b0e
postcss@8.4.14
8.5.23
1
fallenbagel/jellyseerr:latest4538137bc5af
postcss@8.4.31
8.5.23
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
postcss@8.4.14
8.5.23
1
felipecs8/conversor-temperatura:v1f945423be36d
postcss@8.5.8
8.5.23
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
postcss@6.0.22
8.5.23
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
postcss@8.4.31
8.5.23
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
postcss@8.5.16
8.5.23
1
fosrl/pangolin:1.13.0c32ad797ab96
postcss@8.4.31
8.5.23
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
postcss@7.0.39
8.5.23
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
postcss@8.4.23
8.5.23
1
henrywhitaker3/speedtest-tracker:latest47159a940229
postcss@6.0.23
8.5.23
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
postcss@7.0.39
8.5.23
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
postcss@8.5.3
8.5.23
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
postcss@8.4.47
8.5.23
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
postcss@7.0.5
8.5.23
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
postcss@6.0.23
8.5.23
1
ibmcom/microclimate-portal:latested5505e5c7ec
postcss@6.0.17
8.5.23
1
instill/console:0.68.54cd70e2df5c6
postcss@8.5.6
8.5.23
1
jayfong/yapi:1.10.2163e5d621910
postcss@5.2.18
8.5.23
1
joplin/server:3.0-beta52af57880c0e
postcss@8.4.24
8.5.23
1
joplin/server:2.14.2-betab87564ef34e9
postcss@8.4.31
8.5.23
1
jupyterhub/jupyterhub:5.4.63974ba945e65
postcss@8.4.31
node-postcss@8.4.31+~cs8.0.26-1
8.5.23
no fix listed
1
keyoxide/keyoxide:stable96f27a71269d
postcss@8.4.11
8.5.23
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
postcss@7.0.39
8.5.23
1
konradkleine/docker-registry-frontend:v2181aad54ee64
postcss@4.1.16
8.5.23
1
kyleslugg/klusterview:latestba8c36dfdfbd
postcss@8.4.24
8.5.23
1
kyso/kyso-front:lateste52595c5c16f
postcss@8.4.30
8.5.23
1
langgenius/dify-web:0.6.11a2a294743634
postcss@8.4.31
8.5.23
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
postcss@8.4.31
8.5.23
1
langgenius/dify-web:1.0.0d64914ff0d6d
postcss@8.4.31
8.5.23
1
lavandadelpatio/frontend:latest501c3f31e0bc
postcss@7.0.30
8.5.23
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
postcss@8.4.38
8.5.23
1
library/ghost:6.37.01ef2e532ca4d
postcss@8.5.6
8.5.23
1
library/ghost:6.25.12654b1e90413
postcss@8.5.6
8.5.23
1
library/ghost:6.41.129773d6be407
postcss@8.5.6
8.5.23
1
library/ghost:4.37.0767230c0f263
postcss@8.4.6
8.5.23
1
library/ghost:6.39.0-alpine77196da4b0df
postcss@8.5.6
8.5.23
1
library/ghost:5.79.083f7bf209844
postcss@8.4.33
8.5.23
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
postcss@8.5.6
8.5.23
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
postcss@7.0.36
8.5.23
1
linuxserver/codimd:latestb801bbcf6386
postcss@7.0.35
8.5.23
1
linuxserver/overseerr:1.35.06108ed066d4a
postcss@8.4.14
8.5.23
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.