StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
406
of 17,787 indexed, latest versions
Container images
428
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 406 of 17,787 indexed charts deploy, on 428 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1428
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

406 by stars
ChartLatestAffected imagesRadar Score
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.1.1

Open the chart page →

3,818
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.1.1

Open the chart page →

948
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.1.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.1.1

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.1.0
10.1.1

Open the chart page →

3,895
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.1.1

Open the chart page →

5,794
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.1.0
10.1.1

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.1.1

Open the chart page →

18,923
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.1.1

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.1.1

Open the chart page →

2,475
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.1.1

Open the chart page →

11,080
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.1.1

Open the chart page →

9,704
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.1.1

Open the chart page →

5,916
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.1.1

Open the chart page →

30,106
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.1.1

Open the chart page →

25,099
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.1.1

Open the chart page →

1,469
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.1.1

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.1.1

Open the chart page →

3,615
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.1.1

Open the chart page →

3,355
multicaicoretechVerified publisher0.4.421 of 5See more

multica icoretech 0.4.42

1 of the 5 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/multica-ai/multica-web:v0.4.43fc937fbbf8e5
ip-address@10.1.0
10.1.1

Open the chart page →

2,730
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.1.1

Open the chart page →

3,181
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.1.1

Open the chart page →

6,282
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.1.1

Open the chart page →

1,236
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.1.1

Open the chart page →

11,838
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
ip-address@9.0.5
10.1.1

Open the chart page →

2,954
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.1.1

Open the chart page →

3,448
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.1.1

Open the chart page →

5,826
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.1.0
10.1.1

Open the chart page →

425
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.1.1

Open the chart page →

914
github-exporterjkroepkeVerified publisher1.4.01 of 1See more

github-exporter jkroepke 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.1.1

Open the chart page →

1,032
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.1.1

Open the chart page →

22,665
shinsei-managerjtektVerified publisher0.2.03 of 8See more

shinsei-manager jtekt 0.2.0

3 of the 8 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.1.1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.1.1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.1.1

Open the chart page →

59,560
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.1.1

Open the chart page →

1,967
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.1.1

Open the chart page →

2,622
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.1.1

Open the chart page →

8,879
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.1.1

Open the chart page →

2,351
floodk8s-home-lab-repo7.3.01 of 1See more

flood k8s-home-lab-repo 7.3.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.1.1

Open the chart page →

746
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.1.1

Open the chart page →

3,040
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.1.1

Open the chart page →

2,439
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
ip-address@9.0.5
10.1.1

Open the chart page →

974
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
ip-address@9.0.5
10.1.1

Open the chart page →

5,098
keycloak-multi-client-notifierkeycloak-multi-client-notifier2.1.21 of 2See more

keycloak-multi-client-notifier keycloak-multi-client-notifier 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
ip-address@9.0.5
10.1.1

Open the chart page →

1,473
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.1.1

Open the chart page →

1,290
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
ip-address@9.0.5
10.1.1

Open the chart page →

8,680
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
ip-address@10.0.1
10.1.1

Open the chart page →

3,442
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
ip-address@10.1.0
10.1.1

Open the chart page →

8,455
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.1.0
10.1.1

Open the chart page →

2,757
homepagekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

homepage kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
ip-address@10.1.0
10.1.1

Open the chart page →

1,379
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
ip-address@10.1.0
10.1.1

Open the chart page →

1,499
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
ip-address@9.0.5
10.1.1

Open the chart page →

2,549

Container images carrying it

428 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
ip-address@9.0.5
10.1.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
ip-address@9.0.5
10.1.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
ip-address@9.0.5
10.1.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
ip-address@10.1.0
10.1.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
ip-address@9.0.5
10.1.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
ip-address@9.0.5
10.1.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
ip-address@10.1.0
10.1.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
ip-address@10.1.0
10.1.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.1.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.1.1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.1.1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
ip-address@9.0.5
10.1.1
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ip-address@6.4.0
10.1.1
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ip-address@10.1.0
10.1.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
ip-address@10.1.0
10.1.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
ip-address@10.1.0
10.1.1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
ip-address@9.0.5
10.1.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
ip-address@9.0.5
10.1.1
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
ip-address@9.0.5
10.1.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.1.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.1.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.1.1
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
ip-address@9.0.5
10.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
ip-address@10.1.0
10.1.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.