StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
406
of 17,787 indexed, latest versions
Container images
428
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 406 of 17,787 indexed charts deploy, on 428 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1428
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

406 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.1.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.1.1

Open the chart page →

5,472
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.1.1

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.1.1

Open the chart page →

14,172
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.1.1

Open the chart page →

9,381

Container images carrying it

428 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
speckle/speckle-server:2.26.379f14a2bf931
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
ip-address@9.0.5
10.1.1
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
ip-address@9.0.5
10.1.1
1
supabase/postgres-meta:v0.96.6a84cc713585e
ip-address@9.0.5
10.1.1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
ip-address@9.0.5
10.1.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.1.0
10.1.1
1
supabase/storage-api:latestf6c42a04163d
ip-address@10.1.0
10.1.1
1
supabase/storage-api:v1.12.0f983fb50bd95
ip-address@9.0.5
10.1.1
1
supabase/studio:20241021-9f9b08326d8070c55e9
ip-address@9.0.5
10.1.1
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
ip-address@10.1.0
10.1.1
1
supabase/studio:latest94a2a9d2906e
ip-address@10.1.0
10.1.1
1
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.1.1
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.1.1
1
tensorzero/ui:2026.6.0f2563d54724e
ip-address@10.0.1
10.1.1
1
th0th/node-red:4.0.3-debiand06fa39f7406
ip-address@9.0.5
10.1.1
1
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.1.1
1
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
ip-address@9.0.5
10.1.1
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
ip-address@9.0.5
10.1.1
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
ip-address@9.0.5
10.1.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.1.0
10.1.1
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.1.1
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
ip-address@10.1.0
10.1.1
1
unleashorg/unleash-proxy:v1.4.82538f89e2685
ip-address@9.0.5
10.1.1
1
unleashorg/unleash-server:7.5.09adb37e399ba
ip-address@10.0.1
10.1.1
1
vabene1111/recipes:2.3.50f8d061895e9
ip-address@9.0.5
10.1.1
1
vcnngr/pnbackend:latesteaf44ad0ad1f
ip-address@9.0.5
10.1.1
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
ip-address@9.0.5
10.1.1
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
ip-address@9.0.5
10.1.1
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
ip-address@9.0.5
10.1.1
1
wazuh/wazuh-dashboard:4.4.11787550d2358
ip-address@6.4.0
10.1.1
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.1.1
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
ip-address@9.0.5
10.1.1
1
wettyoss/wetty:latest7423b3d40ba2
ip-address@9.0.5
10.1.1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.1.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
ip-address@9.0.5
10.1.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
ip-address@9.0.5
10.1.1
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ip-address@9.0.5
10.1.1
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
ip-address@10.1.0
10.1.1
1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
ip-address@10.1.0
10.1.1
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
ip-address@10.1.0
10.1.1
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
ip-address@10.1.0
10.1.1
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
ip-address@9.0.5
10.1.1
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
ip-address@9.0.5
10.1.1
1
zimengxiong/excalidash-backend:0.4.271273af713c91
ip-address@9.0.5
10.1.1
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@9.0.5
10.1.1
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
ip-address@9.0.5
10.1.1
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
ip-address@9.0.5
10.1.1
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.