StackRadar

CVE-2026-58042

Medium

Advisory

Published 4 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
85
of 17,781 indexed, latest versions
Container images
76
deployed by those charts
Fix available
1 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 85 of 17,781 indexed charts deploy, on 76 images.

Affected packageAffected versionsFixed inImages
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+42 moreno fix listed62
nodejsapk22.16.0-r2, 22.22.0-r0, 22.23.0-r0, 24.11.1-r0+2 more22.23.2-r0, 24.18.1-r011
nodejs-25apk25.2.1-r0, 25.8.1-r0no fix listed2
nodejs-20apk20.18.3-r0no fix listed1
OSV records
ALPINE-CVE-2026-58042DEBIAN-CVE-2026-58042UBUNTU-CVE-2026-58042CGA-6rpw-vcvw-6cghCGA-7wmp-2r95-9fj5
Also known as
CGA-q823-8hrw-hghq, CGA-w9ch-89cj-3pmm

Charts affected

85 by stars
ChartLatestAffected imagesRadar Score
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nodejs@17.5.0-deb-1nodesource1
no fix listed

Open the chart page →

15,730
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
nodejs@24.11.1-r0
24.18.1-r0

Open the chart page →

3,255
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nodejs@16.19.1-deb-1nodesource1
no fix listed

Open the chart page →

10,627
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
nodejs@24.15.0-1nodesource1
no fix listed

Open the chart page →

7,633
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
nodejs@18.20.4-1nodesource1
no fix listed

Open the chart page →

18,813
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
nodejs@22.16.0-1nodesource1
no fix listed

Open the chart page →

9,653
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed

Open the chart page →

57,669
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
nodejs@22.23.0-r0
22.23.2-r0

Open the chart page →

1,235
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
nodejs@18.19.0+dfsg-6~deb12u2
no fix listed

Open the chart page →

10,780
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed

Open the chart page →

8,811
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
nodejs@16.14.2-deb-1nodesource1
no fix listed

Open the chart page →

9,783
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
nodejs@14.21.2-deb-1nodesource1
no fix listed

Open the chart page →

16,417
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
nodejs@24.19.0-1nodesource1
no fix listed

Open the chart page →

12,062
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
nodejs@18.20.8-1nodesource1
no fix listed

Open the chart page →

20,204
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
nodejs@16.20.2-1nodesource1
no fix listed

Open the chart page →

4,232
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
nodejs@20.19.2-1nodesource1
no fix listed

Open the chart page →

37,942
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
nodejs@24.11.1-r0
24.18.1-r0

Open the chart page →

1,391
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
nodejs@10.19.0~dfsg-3ubuntu1
no fix listed

Open the chart page →

17,779
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
nodejs@24.15.0-1nodesource1
no fix listed

Open the chart page →

8,303
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
no fix listed

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
nodejs@8.9.4-1nodesource1
no fix listed

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
no fix listed

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed

Open the chart page →

36,215
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nodejs@14.17.5-deb-1nodesource1
no fix listed

Open the chart page →

11,909
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
nodejs@22.16.0-r2
22.23.2-r0

Open the chart page →

4,499
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
nodejs@26.8.1-1nodesource1
no fix listed

Open the chart page →

3,707
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
nodejs-25@25.8.1-r0
no fix listed

Open the chart page →

5,201
frontendsignalen4.24.01 of 1See more

frontend signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
signalen/frontend:2.27.81ab79cb7fe21
nodejs@24.14.1-r0
24.18.1-r0

Open the chart page →

1,161
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nodejs@10.19.0~dfsg-3ubuntu1.3
no fix listed

Open the chart page →

10,902
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed

Open the chart page →

7,248
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed

Open the chart page →

9,347
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
nodejs@24.20.0-1nodesource1
no fix listed

Open the chart page →

1,961
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-58042.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100

Container images carrying it

76 by charts deploying them

A fixed version is listed for 1 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
nodejs@22.23.2-1nodesource1
no fix listed
1
psorab/elibrary:latest53b68896c4ce
nodejs@16.20.0-deb-1nodesource1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nodejs@18.13.0+dfsg1-1
no fix listed
1
signalen/frontend:2.27.81ab79cb7fe21
nodejs@24.14.1-r0
24.18.1-r0
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
nodejs@20.19.2-1nodesource1
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nodejs@10.19.0~dfsg-3ubuntu1.3
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
nodejs@7.10.1-2nodesource1~xenial1
no fix listed
1
vabene1111/recipes:2.3.50f8d061895e9
nodejs@22.16.0-r2
22.23.2-r0
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nodejs@16.19.1-deb-1nodesource1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nodejs@20.20.0-1nodesource1
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nodejs@16.19.1-deb-1nodesource1
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
nodejs@18.20.4-1nodesource1
no fix listed
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
nodejs@20.20.0-1nodesource1
no fix listed
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nodejs@18.20.4+dfsg-1~deb12u1
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nodejs@17.5.0-deb-1nodesource1
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
nodejs@14.17.2-deb-1nodesource1
no fix listed
1
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
nodejs-25@25.2.1-r0
no fix listed
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
nodejs@18.20.8-1nodesource1
no fix listed
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
nodejs@24.14.1-r0
24.18.1-r0
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
nodejs@24.17.0-r0
24.18.1-r0
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
nodejs@26.8.1-1nodesource1
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
nodejs@24.20.0-1nodesource1
no fix listed
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
nodejs@24.14.1-r0
24.18.1-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.