StackRadar

CVE-2026-42037

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
154
deployed by those charts
Fix available
1 of 1
affected package

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 154 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.1.3, 1.2.1, 1.2.2, 1.2.5+36 more1.15.1154
OSV records
GHSA-445q-vr5w-6q77

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-42037.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
axios@1.12.2
1.15.1

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-42037.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.15.1

Open the chart page →

6,285
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-42037.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
axios@1.3.5
1.15.1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
axios@1.3.5
1.15.1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
axios@1.3.5
1.15.1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
axios@1.3.5
1.15.1

Open the chart page →

16,083

Container images carrying it

154 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.