StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
565
of 18,035 indexed, latest versions
Container images
584
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 565 of 18,035 indexed charts deploy, on 584 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed584
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

565 by stars
ChartLatestAffected imagesRadar Score
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,671
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sprintf-js@1.1.3
no fix listed

Open the chart page →

41,499
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,160
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed

Open the chart page →

37,502
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,818
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
sprintf-js@1.1.3
no fix listed
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,882
efklovemew67Verified publisher0.0.11 of 2See more

efk lovemew67 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nshou/elasticsearch-kibana:kibana7a1d1e36814d1
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,456
mongo_guilovemew67Verified publisher0.0.21 of 1See more

mongo_gui lovemew67 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.1.1e3952b14ae8e
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,247
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,165
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,336
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,814
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,158
homepagem0sh1-helm-charts0.3.11 of 1See more

homepage m0sh1-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.11.0b129cb0f674b
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,976
wudm0sh1-helm-charts0.2.01 of 1See more

wud m0sh1-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
getwud/wud:8.1.1b1cd01c43839
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,829
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
sprintf-js@1.1.3
no fix listed

Open the chart page →

31,422
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
sprintf-js@1.1.3
no fix listed

Open the chart page →

13,747
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,534
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,458
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,654
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,120
claude-code-apimcp-helmVerified publisher0.1.11 of 1See more

claude-code-api mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
arbuzov/claude-code-api:0.1.02d7dd8070610
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,685
mcp-gitlabmcp-helmVerified publisher0.3.41 of 1See more

mcp-gitlab mcp-helm 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,296
mcp-kubernetesmcp-helmVerified publisher0.2.71 of 1See more

mcp-kubernetes mcp-helm 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mcp/kubernetes:latest5ffbf7f0a8aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,466
mcpomcp-helmVerified publisher0.2.81 of 1See more

mcpo mcp-helm 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,933
mcp-playwrightmcp-helmVerified publisher0.1.11 of 1See more

mcp-playwright mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,652
searchmcp-helmVerified publisher0.1.31 of 2See more

search mcp-helm 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
laituanmanh/websearch-crawler:latest63b6da557c71
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,796
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,864
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed

Open the chart page →

88,945
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,572
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,032
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
sprintf-js@1.0.3
no fix listed

Open the chart page →

116,577
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,077
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed

Open the chart page →

11,596
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,743
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,743
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

13,164
finance-portalmojaloop5.1.46 of 11See more

finance-portal mojaloop 5.1.4

6 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed

Open the chart page →

16,967
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,263
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed

Open the chart page →

20,648
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,161
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,019
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,852
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,922
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,334
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,554
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,851
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,148
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,155
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,072
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
sprintf-js@1.1.3
no fix listed

Open the chart page →

13,728

Container images carrying it

584 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
sprintf-js@1.1.3
no fix listed
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
sprintf-js@1.1.3
no fix listed
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
sprintf-js@1.1.3
no fix listed
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
sprintf-js@1.1.3
no fix listed
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
sprintf-js@1.1.3
no fix listed
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
sprintf-js@1.1.3
no fix listed
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
sprintf-js@1.0.3
no fix listed
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
sprintf-js@1.0.3
no fix listed
1
ghcr.io/nicholaswilde/cryptpad:version-4.10.0139d35a0275a
sprintf-js@1.0.3
no fix listed
1
ghcr.io/nicholaswilde/etherpad:version-1.8.1426bbd45110d5
sprintf-js@1.1.2
no fix listed
1
ghcr.io/nmshd/connector:7.5.39759ea1a9e9e
sprintf-js@1.0.3
no fix listed
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/platform-mesh/portal:v0.27.3966b1a9378b6
sprintf-js@1.0.3
no fix listed
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
sprintf-js@1.1.3
no fix listed
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
sprintf-js@1.1.3
no fix listed
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
sprintf-js@1.0.3
no fix listed
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
sprintf-js@1.0.3
no fix listed
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
sprintf-js@1.1.2
no fix listed
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
sprintf-js@1.1.3
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
sprintf-js@1.1.3
no fix listed
1
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
sprintf-js@1.1.3
no fix listed
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
sprintf-js@1.1.3
no fix listed
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
sprintf-js@1.1.3
no fix listed
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
sprintf-js@1.1.3
no fix listed
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
sprintf-js@1.1.3
no fix listed
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
sprintf-js@1.1.3
no fix listed
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
sprintf-js@1.1.3
no fix listed
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
sprintf-js@1.1.3
no fix listed
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
sprintf-js@1.1.3
no fix listed
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
sprintf-js@1.1.3
no fix listed
1
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
sprintf-js@1.0.3
no fix listed
1
ghcr.io/zazukoians/qlever-ui:v0.10.3c27e20f7a2ca
sprintf-js@1.1.3
no fix listed
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
sprintf-js@1.0.3
no fix listed
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
sprintf-js@1.1.3
no fix listed
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.