StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 18,035 indexed, latest versions
Container images
585
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 567 of 18,035 indexed charts deploy, on 585 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed585
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,885
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,360
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,856
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,933
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,249
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,088
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,568
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,227
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
sprintf-js@1.1.3
no fix listed
frinx/frinx-inventory-server:7.0.16b1992c79e78
sprintf-js@1.1.3
no fix listed

Open the chart page →

49,865
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,018
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,271
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,119
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
sprintf-js@1.1.2
no fix listed

Open the chart page →

1,078
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,414
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,391
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,251
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,216
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,889
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
node-sprintf-js@1.1.2+ds1+~1.1.2-1
sprintf-js@1.1.3
no fix listed
no fix listed

Open the chart page →

7,313
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
sprintf-js@1.0.3
no fix listed

Open the chart page →

37,657
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,456
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,333
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,071
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/collector-dynamic:v1.3.06d3d1a5b46a9
sprintf-js@1.1.2
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

26,249
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed

Open the chart page →

56,631
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,651
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,140
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,111
cardinalhbjy0.4.01 of 1See more

cardinal hbjy 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hbjy/cardinal:v1.2.29b80656585cc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,139
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,241
zigbee2mqtthelm-chart-roeiVerified publisher1.19.01 of 1See more

zigbee2mqtt helm-chart-roei 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,258
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
sprintf-js@1.0.3
no fix listed

Open the chart page →

91,741
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,096
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,546
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,195
appwritehelmforgeVerified publisher2.0.31See more

appwrite helmforge 2.0.3

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
appwrite/new:1.1.159-self-hosted1811ce1d8154
sprintf-js@1.0.3
no fix listed

Open the chart page →

—
automatischhelmforgeVerified publisher1.3.91See more

automatisch helmforge 1.3.9

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
sprintf-js@1.0.3
no fix listed

Open the chart page →

—
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
sprintf-js@1.1.3
no fix listed

Open the chart page →

75,877
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,711
dawarichhelmforgeVerified publisher1.0.31See more

dawarich helmforge 1.0.3

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed

Open the chart page →

—
middlewarehelmforgeVerified publisher1.2.81See more

middleware helmforge 1.2.8

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
sprintf-js@1.1.3
no fix listed

Open the chart page →

—
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,604
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,897
webodmhelmforgeVerified publisher1.0.02 of 4See more

webodm helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opendronemap/nodeodm:3.6.2fcd99eb23d8d
sprintf-js@1.0.3
no fix listed
webodm/webodm_webapp:3.3.0ed7b1aa0e40f
sprintf-js@1.0.3
no fix listed

Open the chart page →

22,394
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
sprintf-js@1.0.3
no fix listed

Open the chart page →

25,785
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,609
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,376
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,082

Container images carrying it

585 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
sprintf-js@1.0.3
no fix listed
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
sprintf-js@1.1.3
no fix listed
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
sprintf-js@1.1.3
no fix listed
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
sprintf-js@1.1.3
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
sprintf-js@1.1.3
no fix listed
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
sprintf-js@1.1.3
no fix listed
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
sprintf-js@1.1.3
no fix listed
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
sprintf-js@1.0.3
no fix listed
1
ghcr.io/nicholaswilde/cryptpad:version-4.10.0139d35a0275a
sprintf-js@1.0.3
no fix listed
1
ghcr.io/nicholaswilde/etherpad:version-1.8.1426bbd45110d5
sprintf-js@1.1.2
no fix listed
1
ghcr.io/nmshd/connector:7.5.39759ea1a9e9e
sprintf-js@1.0.3
no fix listed
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/platform-mesh/portal:v0.27.3966b1a9378b6
sprintf-js@1.0.3
no fix listed
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
sprintf-js@1.1.3
no fix listed
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
sprintf-js@1.1.3
no fix listed
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
sprintf-js@1.0.3
no fix listed
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
sprintf-js@1.0.3
no fix listed
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
sprintf-js@1.1.2
no fix listed
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
sprintf-js@1.1.3
no fix listed
1
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
sprintf-js@1.1.3
no fix listed
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
sprintf-js@1.1.3
no fix listed
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
sprintf-js@1.1.3
no fix listed
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
sprintf-js@1.1.3
no fix listed
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
sprintf-js@1.1.3
no fix listed
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
sprintf-js@1.1.3
no fix listed
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
sprintf-js@1.1.3
no fix listed
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
sprintf-js@1.1.3
no fix listed
1
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
sprintf-js@1.0.3
no fix listed
1
ghcr.io/zazukoians/qlever-ui:v0.10.3c27e20f7a2ca
sprintf-js@1.1.3
no fix listed
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
sprintf-js@1.0.3
no fix listed
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.