StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
405
of 17,781 indexed, latest versions
Container images
427
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 405 of 17,781 indexed charts deploy, on 427 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1427
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

405 by stars
ChartLatestAffected imagesRadar Score
umamikubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

umami kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
ip-address@10.1.0
10.1.1

Open the chart page →

2,596
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.1.1

Open the chart page →

6,356
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
ip-address@9.0.5
10.1.1

Open the chart page →

2,509
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
ip-address@9.0.5
10.1.1

Open the chart page →

16,877
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
ip-address@9.0.5
10.1.1

Open the chart page →

20,204
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
ip-address@9.0.5
10.1.1

Open the chart page →

1,119
helm-pilotlbenicio-communityVerified publisher0.2.41 of 1See more

helm-pilot lbenicio-community 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.1.1

Open the chart page →

710
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
ip-address@9.0.5
10.1.1

Open the chart page →

3,555
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.1.1

Open the chart page →

2,600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.1.0
10.1.1

Open the chart page →

33,242
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
ip-address@9.0.5
10.1.1

Open the chart page →

1,344
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
ip-address@9.0.5
10.1.1

Open the chart page →

37,942
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.1.1

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.1.1

Open the chart page →

1,391
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.1.0
10.1.1

Open the chart page →

33,242
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
ip-address@9.0.5
10.1.1

Open the chart page →

1,490
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@9.0.5
10.1.1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@9.0.5
10.1.1

Open the chart page →

2,774
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
ip-address@10.1.0
10.1.1

Open the chart page →

1,852
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
ip-address@9.0.5
10.1.1

Open the chart page →

4,647
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
ip-address@9.0.5
10.1.1

Open the chart page →

24,400
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
ip-address@9.0.5
10.1.1

Open the chart page →

10,897
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.1.1

Open the chart page →

8,303
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
ip-address@9.0.5
10.1.1

Open the chart page →

9,668
miot-appmicroboxlabs0.3.31 of 1See more

miot-app microboxlabs 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
ip-address@10.1.0
10.1.1

Open the chart page →

509
miot-docsmicroboxlabs0.1.11 of 1See more

miot-docs microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-docs:lateste09d92c61f43
ip-address@10.1.0
10.1.1

Open the chart page →

378
miot-stackmicroboxlabs0.2.21 of 2See more

miot-stack microboxlabs 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
ip-address@10.1.0
10.1.1

Open the chart page →

509
modulariotmicroboxlabs0.9.02 of 4See more

modulariot microboxlabs 0.9.0

2 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
ip-address@10.1.0
10.1.1
ghcr.io/microboxlabs/miot-docs:latest0307d2fd9f5c
ip-address@10.1.0
10.1.1

Open the chart page →

2,256
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
ip-address@9.0.5
10.1.1

Open the chart page →

13,010
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ip-address@6.4.0
10.1.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ip-address@6.4.0
10.1.1

Open the chart page →

10,603
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ip-address@10.0.1
10.1.1

Open the chart page →

2,457
finance-portalmojaloop5.1.45 of 11See more

finance-portal mojaloop 5.1.4

5 of the 11 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ip-address@9.0.5
10.1.1
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
ip-address@9.0.5
10.1.1
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ip-address@9.0.5
10.1.1
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
ip-address@9.0.5
10.1.1
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ip-address@9.0.5
10.1.1

Open the chart page →

14,809
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
ip-address@9.0.5
10.1.1

Open the chart page →

800
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ip-address@9.0.5
10.1.1

Open the chart page →

2,631
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
ip-address@9.0.5
10.1.1

Open the chart page →

1,661
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ip-address@9.0.5
10.1.1

Open the chart page →

2,318
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ip-address@9.0.5
10.1.1

Open the chart page →

1,948
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ip-address@10.0.1
10.1.1

Open the chart page →

2,457
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
ip-address@10.1.0
10.1.1

Open the chart page →

2,396
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
ip-address@9.0.5
10.1.1

Open the chart page →

5,179
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.1.1

Open the chart page →

11,643
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.1.1

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.1.1

Open the chart page →

4,960
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
ip-address@10.1.0
10.1.1

Open the chart page →

4,016
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ip-address@9.0.5
10.1.1

Open the chart page →

17,929
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.1.0
10.1.1

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
ip-address@10.1.0
10.1.1

Open the chart page →

1,166
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
ip-address@9.0.5
10.1.1

Open the chart page →

7,184
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
ip-address@9.0.5
10.1.1

Open the chart page →

1,569
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ip-address@9.0.5
10.1.1

Open the chart page →

2,383

Container images carrying it

427 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
ip-address@10.1.0
10.1.1
1
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.1.1
1
baserow/baserow:1.30.1df0c42eb67e8
ip-address@9.0.5
10.1.1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
ip-address@9.0.5
10.1.1
1
bluerange/bluerange-mosquitto:25f1bfbba84832
ip-address@10.0.1
10.1.1
1
bnjbvr/kresus:0.22.137e216b182c8
ip-address@9.0.5
10.1.1
1
budibase/apps:3.41.344fe6feab985
ip-address@10.1.0
10.1.1
1
budibase/database:2.1.0d90f656261c9
ip-address@10.1.0
10.1.1
1
budibase/worker:3.41.3de5e2e560ce8
ip-address@10.1.0
10.1.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
ip-address@9.0.5
10.1.1
1
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.1.1
1
cccs/assemblyline-ui-frontend:4.7.4.stable174c8e4b6c0483
ip-address@10.1.0
10.1.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
ip-address@9.0.5
10.1.1
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip-address@9.0.5
10.1.1
1
chatwoot/chatwoot:v4.15.167ebc751c171
ip-address@10.1.0
10.1.1
1
chibisafe/chibisafe:latest836467a50792
ip-address@9.0.5
10.1.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
ip-address@9.0.5
10.1.1
1
chocobozzz/peertube:v8.1.5052712130691
ip-address@9.0.5
10.1.1
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
ip-address@9.0.5
10.1.1
1
codetogether/codetogether:latest4348c8a38752
ip-address@9.0.5
10.1.1
1
contane/foreman:0.5.2efb98bdcc4e9
ip-address@9.0.5
10.1.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.1.1
1
countly/api:25.05.4f4cc7447c4f5
ip-address@5.9.4
10.1.1
1
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.1.1
1
countly/frontend:25.05.42acbc11499b6
ip-address@5.9.4
10.1.1
1
cspconsole/report-processor:1.0.279a2d8840bfdf
ip-address@10.1.0
10.1.1
1
dbgate/dbgate:7.2.0-alpine287077002446
ip-address@9.0.5
10.1.1
1
dbgate/dbgate:7.2.3f2dc7423ea88
ip-address@10.1.0
10.1.1
1
decisionrules/business-intelligence:latest1135a6d4f09b
ip-address@10.1.0
10.1.1
1
defactops/defactops-backend:1.0.2307b663c0092a
ip-address@9.0.5
10.1.1
1
devkrishan001/backend:latestf1c3acadeabe
ip-address@9.0.5
10.1.1
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.1.1
1
devravinder/node-express-app:1.0.05325a96967b5
ip-address@9.0.5
10.1.1
1
directus/directus:12.0.29c8470ea465c
ip-address@10.1.0
10.1.1
1
directus/directus:11.1.0e3c8bb975350
ip-address@9.0.5
10.1.1
1
diygod/rsshub:2025-11-097a6312cac0d5
ip-address@10.0.1
10.1.1
1
docmost/docmost:0.95.041c8d777cf23
ip-address@10.1.0
10.1.1
1
documenso/documenso:v1.8.17f16a9449f18
ip-address@9.0.5
10.1.1
1
drumsergio/genieacs:1.2.16.028244054e1bf
ip-address@10.1.0
10.1.1
1
drumsergio/lynxprompt:2.0.75c6afb6679301
ip-address@10.1.0
10.1.1
1
drumsergio/pumperly:1.4.885bbc3915e9e
ip-address@10.1.0
10.1.1
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.1.0
10.1.1
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
ip-address@9.0.5
10.1.1
1
etherpad/etherpad:2.7.2b723fe5f2594
ip-address@10.1.0
10.1.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ip-address@9.0.5
10.1.1
1
ethpandaops/ethereumjs:masterfb84b718500f
ip-address@9.0.5
10.1.1
1
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.1.1
1
fallenbagel/jellyseerr:latest4538137bc5af
ip-address@9.0.5
10.1.1
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
ip-address@9.0.5
10.1.1
1
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.