StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
405
of 17,781 indexed, latest versions
Container images
427
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 405 of 17,781 indexed charts deploy, on 427 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1427
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

405 by stars
ChartLatestAffected imagesRadar Score
supabasesupabse0.8.03 of 11See more

supabase supabse 0.8.0

3 of the 11 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.96.6a84cc713585e
ip-address@9.0.5
10.1.1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.1.0
10.1.1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
ip-address@10.1.0
10.1.1

Open the chart page →

18,075
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
ip-address@9.0.5
10.1.1

Open the chart page →

12,581
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
ip-address@9.0.5
10.1.1

Open the chart page →

4,010
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
ip-address@9.0.5
10.1.1

Open the chart page →

5,225
wachdwachdVerified publisher0.4.371 of 1See more

wachd wachd 0.4.37

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/wachd/wachd:0.4.1805b05c56da94
ip-address@10.1.0
10.1.1

Open the chart page →

1,269
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.1.1

Open the chart page →

3,833
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.1.1

Open the chart page →

10,090
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
ip-address@9.0.5
10.1.1

Open the chart page →

2,900
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
ip-address@10.0.1
10.1.1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
ip-address@9.0.5
10.1.1

Open the chart page →

3,600
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
ip-address@10.1.0
10.1.1

Open the chart page →

1,055
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
ip-address@10.1.0
10.1.1

Open the chart page →

3,820
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.1.0
10.1.1

Open the chart page →

30,028
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.1.0
10.1.1

Open the chart page →

523
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
ip-address@10.1.0
10.1.1

Open the chart page →

6,486
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.1.1

Open the chart page →

4,880
homepagealareira1.0.11 of 1See more

homepage alareira 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:latest753eeb0cc22a
ip-address@10.1.0
10.1.1

Open the chart page →

352
cross-seedalekcVerified publisher7.19.01 of 1See more

cross-seed alekc 7.19.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.1.1

Open the chart page →

1,384
excalidashalekcVerified publisher1.4.01 of 2See more

excalidash alekc 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@9.0.5
10.1.1

Open the chart page →

904
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.1.1

Open the chart page →

5,558
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
ip-address@10.1.0
10.1.1

Open the chart page →

690
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0b6a67099e4c5
ip-address@9.0.5
10.1.1

Open the chart page →

4,923
assemblylineassemblylineVerified publisher7.4.171 of 12See more

assemblyline assemblyline 7.4.17

1 of the 12 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
cccs/assemblyline-ui-frontend:4.7.4.stable174c8e4b6c0483
ip-address@10.1.0
10.1.1

Open the chart page →

12,898
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.1.1

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
wettyoss/wetty:latest7423b3d40ba2
ip-address@9.0.5
10.1.1

Open the chart page →

7,152
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.1.1

Open the chart page →

1,722
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.1.1

Open the chart page →

2,136
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
ip-address@10.0.1
10.1.1

Open the chart page →

1,168
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.1.1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.1.1

Open the chart page →

26,996
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.1.1

Open the chart page →

1,477
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.1.1

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.1.1

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.1.1

Open the chart page →

1,306
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.1.1

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.1.1

Open the chart page →

1,338
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.1.1

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.1.1

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.1.1

Open the chart page →

1,722
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ip-address@9.0.5
10.1.1

Open the chart page →

1,977
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.1.1

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
ip-address@5.9.4
10.1.1
countly/frontend:25.05.42acbc11499b6
ip-address@5.9.4
10.1.1

Open the chart page →

7,295
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ip-address@10.1.0
10.1.1

Open the chart page →

1,947
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.1.1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.1.1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.1.1

Open the chart page →

18,293
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.1.1

Open the chart page →

2,184
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
ip-address@9.0.5
10.1.1

Open the chart page →

3,868
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.1.1

Open the chart page →

1,527
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.1.1

Open the chart page →

1,598
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.1.1

Open the chart page →

8,368
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.1.1

Open the chart page →

14,559
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
ip-address@6.4.0
10.1.1

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
cspconsole/report-processor:1.0.279a2d8840bfdf
ip-address@10.1.0
10.1.1

Open the chart page →

12,274

Container images carrying it

427 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
ip-address@9.0.5
10.1.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
ip-address@9.0.5
10.1.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
ip-address@10.1.0
10.1.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
ip-address@9.0.5
10.1.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
ip-address@9.0.5
10.1.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
ip-address@10.1.0
10.1.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
ip-address@10.1.0
10.1.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.1.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.1.1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.1.1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
ip-address@9.0.5
10.1.1
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ip-address@6.4.0
10.1.1
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ip-address@10.1.0
10.1.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
ip-address@10.1.0
10.1.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
ip-address@10.1.0
10.1.1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
ip-address@9.0.5
10.1.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
ip-address@9.0.5
10.1.1
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
ip-address@9.0.5
10.1.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.1.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.1.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.1.1
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
ip-address@9.0.5
10.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.