StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
406
of 17,787 indexed, latest versions
Container images
428
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 406 of 17,787 indexed charts deploy, on 428 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1428
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

406 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.1.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.1.1

Open the chart page →

5,472
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.1.1

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.1.1

Open the chart page →

14,172
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.1.1

Open the chart page →

9,381

Container images carrying it

428 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.1.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.1.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.1.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.1.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.1.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.1.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.1.1
1
otwld/velero-ui:0.10.2d1954b759e47
ip-address@10.1.0
10.1.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.1.1
1
penpotapp/exporter:2.2.15c835ffd87ab
ip-address@9.0.5
10.1.1
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
ip-address@10.0.1
10.1.1
1
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.1.1
1
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.1.1
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
ip-address@10.0.1
10.1.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
ip-address@9.0.5
10.1.1
1
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.1.1
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.1.1
1
redis/redisinsight:2.68019fcf774631
ip-address@9.0.5
10.1.1
1
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.1.1
1
redis/redisinsight:2.46699d341bd329
ip-address@9.0.5
10.1.1
1
redis/redisinsight:3.485562d67a912
ip-address@9.0.5
10.1.1
1
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.1.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
ip-address@10.1.0
10.1.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.1.0
10.1.1
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.1.0
10.1.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.1.0
10.1.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.1.0
10.1.1
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ip-address@9.0.5
10.1.1
1
sharanalwar/redchef-frontend:latest5e82950b16b7
ip-address@9.0.5
10.1.1
1
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.1.1
1
shyamkrishna21/shopsync:latest3998b83def53
ip-address@9.0.5
10.1.1
1
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.1.1
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
ip-address@9.0.5
10.1.1
1
skylenet/ethstats-server:pow-latestd757cc016198
ip-address@5.9.4
10.1.1
1
sondresjo/altinnendata-app:v1.9.1c2707839d8a3
ip-address@9.0.5
10.1.1
1
sondresjo/garge-app:v1.20.70382ebf9dfc8
ip-address@9.0.5
10.1.1
1
sondresjo/nstuning-app:v1.6.113a6795bf36da
ip-address@9.0.5
10.1.1
1
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.26.3092384dba45d
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
ip-address@9.0.5
10.1.1
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.