CVE-2026-69153

high Red Hat
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: August 3, 2026 (34 days ago)
Last Modified: August 3, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and expose unintended source-map files, potentially revealing sensitive information about the application's source code.

CWE

CWE-22

Affected Products

Cryostat 4Gatekeeper 3Migration Toolkit for ContainersMulticluster Engine for KubernetesNode HealthCheck OperatorOpenShift LightspeedOpenShift PipelinesOpenShift Service Mesh 3Red Hat 3scale API Management Platform 2Red Hat Advanced Cluster Management for Kubernetes 2

References