CVE-2026-73646

Aliases:GHSA-R28C-9Q8G-F849GHSA-r28c-9q8g-f849DEBIAN-CVE-2026-73646UBUNTU-CVE-2026-73646CGA-282m-c8r7-mqqvCGA-2wp2-25v2-48vgCGA-35vq-7q8r-pgfpCGA-3w6r-vmpq-5j3qCGA-4qwf-f47g-hwf8CGA-6fqx-8f3r-9vrvCGA-6q7r-f3xh-pw29CGA-6rjq-99mr-m66mCGA-88fr-r5mv-6fv9CGA-c5hm-2hc2-3h52CGA-cx5p-fmrv-88g8CGA-fmm2-grhq-wrm8CGA-g7pj-37xr-xxq5CGA-h78v-5334-5wjwCGA-hc7j-mqxh-4v7pCGA-jv7f-rq75-xwfxCGA-m6xh-m393-3j8jCGA-mpg4-8qfw-rhpjCGA-p8w2-7cqh-rm95CGA-pmw4-rgw7-frhgCGA-2287-pvrp-hcfxCGA-2q53-8569-w54jCGA-2qfw-rrhc-6w98CGA-2qr2-v442-6fg3CGA-42c5-2w3r-j9xhCGA-44x3-g426-5p4qCGA-456v-ghmc-rp8rCGA-46qq-82g6-76pqCGA-48w4-8rgq-qpv7CGA-4j9m-vh63-2873CGA-4jfq-34w9-6vq7CGA-4q5x-g3ch-4rpjCGA-4r4r-mjff-m485CGA-4wmc-m5v7-6pjvCGA-549c-r3jg-x2wqCGA-54wx-9x5w-g767CGA-584h-3jp6-4rw2CGA-594m-2fj6-r326CGA-5c63-68p8-gxwfCGA-5chw-3jff-q3qqCGA-5fxq-fjx3-vxm5CGA-5jj9-qqhp-2228CGA-5q5p-r2qv-6mcmCGA-62fg-392j-jvcpCGA-63mx-f7pf-r9c3CGA-6879-mjf4-mfphCGA-6c2w-328q-r4m8CGA-6cmg-h9p6-5p9jCGA-6jmg-3jvf-cv26CGA-726v-7p48-4crmCGA-75v3-hqqh-xj8fCGA-78xp-c7xf-pwcxCGA-793v-7cfv-6r95CGA-7q6j-q78p-jx75CGA-7r78-cj43-2c3jCGA-7rc6-cm9m-w6h2CGA-7v47-9fxm-ff62CGA-7xj2-8fpp-7ffhCGA-823w-c392-96fjCGA-83vh-7c2f-6q5mCGA-88gg-jx82-r9hcCGA-8r99-jg4x-v3p3CGA-8rgh-429p-qpx5CGA-938f-5gf9-2g8fCGA-93hg-q52p-4vj8CGA-93qj-mg49-cc2gCGA-96wr-rjw3-qhxjCGA-995w-49r8-xf97CGA-99h7-q83r-8vcxCGA-9c5j-cmqp-h4r5CGA-9fvq-wg7c-8mp5CGA-9q36-w98v-jrmwCGA-c3mw-j3ph-fwvwCGA-c49f-jpcv-pw26CGA-c5p6-2944-6f76CGA-c778-9p9j-937pCGA-c9gh-rw73-2cp6CGA-c9x5-rf89-9ww6CGA-cc6m-qmgm-h3p3CGA-cjg7-3wh9-8p66CGA-f5fq-784c-hp5vCGA-f8p5-xchp-qq24CGA-ffrw-6whp-4v56CGA-fmrv-mgg7-94p8CGA-g38v-q9x9-56mhCGA-gh9f-93pf-9239CGA-ghhg-5wp5-v6gxCGA-gm46-6cfw-fmf5CGA-gwcj-v288-wrwfCGA-h8mr-x549-7hrqCGA-hch3-rhgx-vcqwCGA-hgjq-gv75-gxh5CGA-hgrm-xg65-44qrCGA-hhxp-vgrx-89qxCGA-hq53-r57p-f962CGA-hv7r-858w-36gmCGA-j2qh-5gxq-8g8fCGA-j384-hqxm-6vvmCGA-j5cj-rfhp-rc76CGA-jcvv-qrm8-r7hrCGA-jgf9-6w69-w3ggCGA-jmg5-rq3g-75x6CGA-m24j-m74v-r534CGA-m2wg-364x-q73xCGA-m2wj-82q2-4ppcCGA-m4h8-q43f-6vfwCGA-mfq3-vx58-2p3rCGA-mj5f-v2f4-9484CGA-mjq7-8r4m-c783CGA-mxf2-pg4v-c3g7CGA-p6cr-94pg-798rCGA-pcc9-7j4f-wmf5CGA-pcwp-f8qp-g57rCGA-pmhx-f38j-28crCGA-pp8c-mh29-whj8CGA-ppxh-2jh4-qrpgCGA-pqqv-h5wj-9w3pCGA-pvrx-r2wf-9q7jCGA-q54m-6qg9-f275CGA-q6w2-jc6c-6mmfCGA-q6xj-cg52-x4whCGA-q8vc-9mr8-5gjpCGA-q9xw-rpvq-mh96CGA-qhfr-3fmw-wcpqCGA-qjm4-569c-87p2CGA-qvmg-2f75-hc8gCGA-qxp4-whjm-r7rxCGA-r23f-4xv3-vmggCGA-r28g-gm4x-2mvrCGA-r62x-h39c-p2jmCGA-r76r-h57f-6ph4CGA-rjj3-46g6-c27gCGA-rm6q-v8rg-rf4xCGA-rwpv-8fvr-6w4qCGA-v43j-c3g4-73x7CGA-v95f-hm9h-mf9mCGA-vg35-62mx-j9ccCGA-vmq8-q77w-34pwCGA-vr6c-p362-25r3CGA-vw6c-2x99-2857CGA-vx8x-m3mm-6hw4CGA-w2hr-7rvr-946xCGA-w47w-5852-4m9jCGA-w68r-vc8c-w34vCGA-w694-vjcm-qw7hCGA-w932-x6jg-h526CGA-wc7w-8wr7-7cj6CGA-wh89-87x7-fr57CGA-whf3-9qvg-58w2CGA-whmg-f5rq-r3qrCGA-wxfw-5jm9-7v4fCGA-x6g7-7387-phc4CGA-x7v8-gfcc-5m69CGA-xc5c-xjh6-w5r2CGA-xg7j-w62q-vpxmCGA-xg98-54w3-88cwCGA-xj3j-xpp8-gv5qCGA-xpc2-hj63-69w7CGA-xpfp-8v5v-8xwhCGA-xprp-m8pc-wmcfCGA-xrhc-25pr-r47hCGA-xxv4-7gr6-gmq2CGA-47gr-cp94-p4f6CGA-5w2m-mqv2-mg34CGA-4fhg-8pf6-9qcpCGA-9fm2-w239-3gr3CGA-3r86-vh4q-5r3qCGA-j2ph-4m5m-qvx6CGA-vxf2-vj3q-m758CGA-xmpr-96h7-p25gCGA-c84w-wxq2-83j6CGA-q2fx-3q4v-4fcx
Advisory lineage Upstream: 0 Downstream: 2
Awaiting Analysis
Published: 17 Aug 2026, 15:35
Last modified:17 Aug 2026, 16:36

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.38% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Aug 2026, 15:35
Published
Vulnerability first disclosed
17 Aug 2026, 16:36
Last Modified
Vulnerability information updated

Description

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.18.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.38% Percentile: 32%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.5-r1

  • chainguardarangodb-3.12

    < 3.12.9.4-r22

  • chainguardauthentik-2025.12

    < 2025.12.6-r6

  • chainguardauthentik-2026.2

    < 2026.2.6-r9

  • chainguardauthentik-2026.5

    < 2026.5.6-r4 | < 2026.5.6-r3

  • chainguardauthentik-fips-2025.12

    all

  • chainguardauthentik-fips-2026.2

    < 2026.2.6-r5

  • chainguardauthentik-fips-2026.5

    < 2026.5.6-r3

  • chainguardcadence-web

    < 4.0.16-r4

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardhomepage

    < 1.13.2-r7

  • chainguardjitsucom-jitsu-console

    < 2.11.0-r30

  • chainguardjupyter-base-notebook

    all

  • chainguardkeep-ui

    < 0.54.2-r2

  • chainguardkeep-ui-fips

    < 0.54.2-r4

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.224.3-r0

  • chainguardlangfuse-fips-3-worker

    < 3.224.2-r0

  • chainguardlibrechat

    < 0.8.7-r5

  • chainguardnextcloud-server-31

    < 31.0.14-r6

  • chainguardnextcloud-server-32

    < 32.0.13-r2

  • chainguardnextcloud-server-33

    < 33.0.8-r1 | < 33.0.8-r0

Showing first 50 affected entries in server-rendered view.

References (9)