StackRadar

CVE-2026-42338

Medium

Advisory

Published 5 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
405
of 17,781 indexed, latest versions
Container images
427
deployed by those charts
Fix available
1 of 1
affected package

ip-address has XSS in Address6 HTML-emitting methods

Carried by container images the latest versions of 405 of 17,781 indexed charts deploy, on 427 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+4 more10.1.1427
OSV records
GHSA-v2v4-37r5-5v8g

Charts affected

405 by stars
ChartLatestAffected imagesRadar Score
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.1.1

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.1.1

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.1.1

Open the chart page →

14,100
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-42338.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.1.1

Open the chart page →

9,381

Container images carrying it

427 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.1.1
4
redis/redisinsight:3.8:latestb5e19ee240ab
ip-address@9.0.5
10.1.1
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.1.1
4
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
ip-address@10.1.0
10.1.1
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
ip-address@10.1.0
10.1.1
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ip-address@10.0.1
10.1.1
3
epamedp/krci-portal:0.8.0687acf641097
ip-address@9.0.5
10.1.1
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.1.1
2
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.1.1
2
infisical/infisical:latest:v0.165.602082bf13163
ip-address@9.0.5
10.1.1
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
ip-address@10.1.0
10.1.1
2
library/ghost:6.63.0e05bc1169fb2
ip-address@10.1.0
10.1.1
2
library/mongo-express:1.0.2:latest1b23d7976f02
ip-address@9.0.5
10.1.1
2
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.1.0
10.1.1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.1.0
10.1.1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.1.0
10.1.1
2
mojaloop/reporting:v12.1.0d480a62103d6
ip-address@9.0.5
10.1.1
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
ip-address@9.0.5
10.1.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ip-address@9.0.5
10.1.1
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
ip-address@9.0.5
10.1.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ip-address@9.0.5
10.1.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ip-address@10.0.1
10.1.1
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
ip-address@6.4.0
10.1.1
2
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.1.1
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.1.1
2
requarks/wiki:2:latest68f0d1848261
ip-address@5.9.4
10.1.1
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
ip-address@9.0.5
10.1.1
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
ip-address@9.0.5
10.1.1
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ip-address@6.1.0
10.1.1
2
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.1.1
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.1.1
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.1.1
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.1.1
2
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.1.1
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.1.0
10.1.1
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
ip-address@9.0.5
10.1.1
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
ip-address@9.0.5
10.1.1
2
aaronshaf/dynamodb-admin:latestac41724cd997
ip-address@10.1.0
10.1.1
1
activepieces/activepieces:0.90.430c10a04fe3d
ip-address@10.1.0
10.1.1
1
activepieces/activepieces:0.23.0c26188b44e62
ip-address@9.0.5
10.1.1
1
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.1.1
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
ip-address@10.0.1
10.1.1
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
ip-address@9.0.5
10.1.1
1
agentarea/agentarea-frontend:latest2098a9d7b1fe
ip-address@10.1.0
10.1.1
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
ip-address@10.1.0
10.1.1
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.1.1
1
alazidis/stornx:1.1.1602d4f7f090c
ip-address@9.0.5
10.1.1
1
alquimiaai/studio:certification38a1f0341982
ip-address@9.0.5
10.1.1
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
ip-address@9.0.5
10.1.1
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
ip-address@9.0.5
10.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.