StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
406
of 17,787 indexed, latest versions
Container images
428
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 406 of 17,787 indexed charts deploy, on 428 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1428
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

406 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.1.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.1.1

Open the chart page →

5,472
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.1.1

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.1.1

Open the chart page →

14,172
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.1.1

Open the chart page →

9,381

Container images carrying it

428 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/node:208f693eaa7e0a
ip-address@9.0.5
10.1.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@9.0.5
10.1.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.1.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.1.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.1.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.1.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.1.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.1.1
1
louislam/uptime-kuma:13d632903e6af
ip-address@9.0.5
10.1.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.1.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.1.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.1.1
1
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.1.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.1.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.1.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.1.1
1
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.1.1
1
mauricenino/dashdot:5.9.2236997816917
ip-address@9.0.5
10.1.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.1.1
1
mcpuse/inspector:latest91b25e3eb604
ip-address@10.1.0
10.1.1
1
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.1.1
1
mishtinetwork/operator:latestbb3fe67a5f7c
ip-address@9.0.5
10.1.1
1
misskey/misskey:12.110.1e08b7c478093
ip-address@7.1.0
10.1.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.1.1
1
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.1.1
1
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.1.1
1
moreillon/food-manager:lateste8fd856e593d
ip-address@9.0.5
10.1.1
1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.1.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.0
10.1.1
1
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.1.1
1
n8nio/n8n:1.33.1dd171d45102a
ip-address@9.0.5
10.1.1
1
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.1.1
1
neoskop/ixy:2.1.125152b474f54
ip-address@10.1.0
10.1.1
1
nocodb/nocodb:0.258.06779a4ddedf2
ip-address@9.0.5
10.1.1
1
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.1.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.1.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.1.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.1.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.1.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.1.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.1.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.1.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.1.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.1.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.1.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.1.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.1.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.1.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.1.1
1
opencti/platform:7.260910.0186fc757c3eb
ip-address@10.1.0
10.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.