StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
405
of 17,781 indexed, latest versions
Container images
427
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 405 of 17,781 indexed charts deploy, on 427 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1427
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

405 by stars
ChartLatestAffected imagesRadar Score
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.1.1

Open the chart page →

3,806
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.1.1

Open the chart page →

948
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.1.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.1.1

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.1.0
10.1.1

Open the chart page →

4,018
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.1.1

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.1.0
10.1.1

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.1.1

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.1.1

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.1.1

Open the chart page →

2,463
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.1.1

Open the chart page →

11,042
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.1.1

Open the chart page →

9,653
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.1.1

Open the chart page →

6,012
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.1.1

Open the chart page →

30,099
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.1.1

Open the chart page →

25,017
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.1.1

Open the chart page →

1,468
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.1.1

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.1.1

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.1.1

Open the chart page →

3,407
multicaicoretechVerified publisher0.4.421 of 5See more

multica icoretech 0.4.42

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/multica-ai/multica-web:v0.4.43fc937fbbf8e5
ip-address@10.1.0
10.1.1

Open the chart page →

2,722
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.1.1

Open the chart page →

3,154
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.1.1

Open the chart page →

6,254
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.1.1

Open the chart page →

1,235
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.1.1

Open the chart page →

11,812
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
ip-address@9.0.5
10.1.1

Open the chart page →

3,014
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.1.1

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.1.1

Open the chart page →

5,826
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.1.0
10.1.1

Open the chart page →

424
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.1.1

Open the chart page →

914
github-exporterjkroepkeVerified publisher1.4.01 of 1See more

github-exporter jkroepke 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.1.1

Open the chart page →

1,031
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.1.1

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.03 of 8See more

shinsei-manager jtekt 0.2.0

3 of the 8 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.1.1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.1.1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.1.1

Open the chart page →

63,461
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.1.1

Open the chart page →

1,966
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.1.1

Open the chart page →

2,611
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.1.1

Open the chart page →

8,811
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.1.1

Open the chart page →

2,350
floodk8s-home-lab-repo7.3.01 of 1See more

flood k8s-home-lab-repo 7.3.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.1.1

Open the chart page →

746
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.1.1

Open the chart page →

3,092
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.1.1

Open the chart page →

2,437
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
ip-address@9.0.5
10.1.1

Open the chart page →

973
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
ip-address@9.0.5
10.1.1

Open the chart page →

5,228
keycloak-multi-client-notifierkeycloak-multi-client-notifier2.1.21 of 2See more

keycloak-multi-client-notifier keycloak-multi-client-notifier 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
ip-address@9.0.5
10.1.1

Open the chart page →

1,473
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.1.1

Open the chart page →

1,290
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
ip-address@9.0.5
10.1.1

Open the chart page →

9,098
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
ip-address@10.0.1
10.1.1

Open the chart page →

3,441
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
ip-address@10.1.0
10.1.1

Open the chart page →

8,405
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.1.0
10.1.1

Open the chart page →

2,756
homepagekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

homepage kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
ip-address@10.1.0
10.1.1

Open the chart page →

1,378
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
ip-address@10.1.0
10.1.1

Open the chart page →

1,498
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
ip-address@9.0.5
10.1.1

Open the chart page →

2,548

Container images carrying it

427 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
felipecs8/landing-page:v1db6d44e325a1
ip-address@9.0.5
10.1.1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip-address@9.0.5
10.1.1
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
ip-address@9.0.5
10.1.1
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
ip-address@9.0.5
10.1.1
1
folioci/mod-graphql:latestf0655a6a08fd
ip-address@9.0.5
10.1.1
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
ip-address@9.0.5
10.1.1
1
fosrl/pangolin:1.13.0c32ad797ab96
ip-address@10.0.1
10.1.1
1
fthomas/scala-steward:latest367afe974b7a
ip-address@10.1.0
10.1.1
1
gethue/hue:latest7d5c1b9f8a79
ip-address@10.1.0
10.1.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.1.1
1
globalping/globalping-probe:latest8acbd23009fd
ip-address@10.1.0
10.1.1
1
haohanyang/compass-web:0.5.054f2112602ee
ip-address@10.1.0
10.1.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ip-address@9.0.5
10.1.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ip-address@9.0.5
10.1.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.1.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.1.1
1
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.1.1
1
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.1.1
1
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.1.1
1
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.1.1
1
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.1.1
1
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.1.1
1
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.1.1
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.1.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.1.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.1.1
1
joplin/server:latest3f7b852959aa
ip-address@9.0.5
10.1.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.1.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.1.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.1.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.1.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.1.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.1.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.1.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.1.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.1.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.1.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.1.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.1.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.1.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.1.1
1
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.1.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.1.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.1.0
10.1.1
1
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.1.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.1.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.1.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.1.1
1
library/node:22-bookworm-slim83f487e0a634
ip-address@10.1.0
10.1.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.