StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
577
of 18,035 indexed, latest versions
Container images
597
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 577 of 18,035 indexed charts deploy, on 597 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed597
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

577 by stars
ChartLatestAffected imagesRadar Score
joplin-serverschoenwald1.0.31 of 1See more

joplin-server schoenwald 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
joplin/server:3.7.23f7b852959aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,975
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
sprintf-js@1.1.3
no fix listed

Open the chart page →

35,474
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
sprintf-js@1.0.3
no fix listed

Open the chart page →

7,175
seerr-chartseerr-chartVerified publisher3.10.01 of 1See more

seerr-chart seerr-chart 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.5.027602401178d
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,264
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,380
shopsyncshopsyncVerified publisher1.0.01 of 1See more

shopsync shopsync 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
shyamkrishna21/shopsync:latest3998b83def53
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,566
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,643
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,431
simple-node-expresssimple-node-express1.0.01 of 1See more

simple-node-express simple-node-express 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
devravinder/node-express-app:1.0.05325a96967b5
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,135
infisicalsinextraVerified publisher0.6.11 of 1See more

infisical sinextra 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.166b911e3938ac
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,374
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
sprintf-js@1.1.2
no fix listed

Open the chart page →

88,006
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
sprintf-js@1.1.2
no fix listed

Open the chart page →

88,006
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,976
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,637
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,541
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,557
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,358
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,559
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e12 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

18,134
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
sprintf-js@1.1.3
no fix listed

Open the chart page →

18,219
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091142 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
sprintf-js@1.1.3
no fix listed

Open the chart page →

18,219
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4692 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d4694bd113093583
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,860
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3412 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.12-branch.testing3.88744-f55b3414bd113093583
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,860
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b22 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
sprintf-js@1.1.3
no fix listed

Open the chart page →

17,788
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef2 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
sprintf-js@1.1.3
no fix listed

Open the chart page →

17,473
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e2 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
sprintf-js@1.1.3
no fix listed
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
sprintf-js@1.1.3
no fix listed

Open the chart page →

12,592
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
sprintf-js@1.0.3
no fix listed

Open the chart page →

1,589
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,640
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,640
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,940
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,157
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
sprintf-js@1.0.3
no fix listed

Open the chart page →

7,006
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
sprintf-js@1.0.3
no fix listed

Open the chart page →

1,331
strapistrapi-xmv0.1.21 of 1See more

strapi strapi-xmv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
sprintf-js@1.0.3
no fix listed

Open the chart page →

957
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,464
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,247
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,913
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,529
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,360
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
sprintf-js@1.1.3
no fix listed

Open the chart page →

12,555
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
sprintf-js@1.1.3
no fix listed

Open the chart page →

42,622
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,287
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
sprintf-js@1.0.3
no fix listed
samajh/alprfrontend:latest05ef4fddbb75
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,025
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,915
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,953
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
catalysm/csmm:lateste8e3d06f1d70
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,790
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,307
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
sprintf-js@1.1.3
no fix listed
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
sprintf-js@1.1.3
no fix listed
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
sprintf-js@1.1.3
no fix listed

Open the chart page →

9,117
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,959
learning-fluentdtungntt0.1.01 of 4See more

learning-fluentd tungntt 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/kibana:7.9.1b1bbcaa57738
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,499

Container images carrying it

597 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
sprintf-js@1.1.3
no fix listed
1
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
sprintf-js@1.1.2
no fix listed
1
ghcr.io/linuxserver/mstream:version-v5.2.522c012bcc43c
sprintf-js@1.0.3
no fix listed
1
ghcr.io/linuxserver/pixapop:v1.2-ls15605ebc091fa1
sprintf-js@1.1.2
no fix listed
1
ghcr.io/linuxserver/projectsend:version-r129540b883bef0cf
sprintf-js@1.1.2
no fix listed
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
sprintf-js@1.1.2
no fix listed
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
sprintf-js@1.0.3
no fix listed
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
sprintf-js@1.1.3
no fix listed
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
sprintf-js@1.1.3
no fix listed
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
sprintf-js@1.1.3
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
sprintf-js@1.1.3
no fix listed
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
sprintf-js@1.1.3
no fix listed
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
sprintf-js@1.1.3
no fix listed
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mend/renovate-ee-server:15.7.063e0ca823222
sprintf-js@1.1.3
no fix listed
1
ghcr.io/nicholaswilde/cryptpad:version-4.10.0139d35a0275a
sprintf-js@1.0.3
no fix listed
1
ghcr.io/nicholaswilde/etherpad:version-1.8.1426bbd45110d5
sprintf-js@1.1.2
no fix listed
1
ghcr.io/nmshd/connector:7.5.39759ea1a9e9e
sprintf-js@1.0.3
no fix listed
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/platform-mesh/portal:v0.27.3966b1a9378b6
sprintf-js@1.0.3
no fix listed
1
ghcr.io/quenchworks/images/uptime-kumad369a6e49131
sprintf-js@1.1.3
no fix listed
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
sprintf-js@1.1.3
no fix listed
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
sprintf-js@1.1.3
no fix listed
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
sprintf-js@1.0.3
no fix listed
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
sprintf-js@1.0.3
no fix listed
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
sprintf-js@1.1.2
no fix listed
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
sprintf-js@1.1.3
no fix listed
1
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
sprintf-js@1.1.3
no fix listed
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
sprintf-js@1.1.3
no fix listed
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
sprintf-js@1.1.3
no fix listed
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
sprintf-js@1.1.3
no fix listed
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
sprintf-js@1.1.3
no fix listed
1
ghcr.io/thm-mni-ii/fbs-qcm-backend:v2.0.7164f59b93e45
sprintf-js@1.1.3
no fix listed
1
ghcr.io/thm-mni-ii/fbs-qcm-frontend:v2.0.7d5aa22a0ffe3
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
sprintf-js@1.1.3
no fix listed
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.