StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
565
of 18,035 indexed, latest versions
Container images
584
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 565 of 18,035 indexed charts deploy, on 584 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed584
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

565 by stars
ChartLatestAffected imagesRadar Score
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,885
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,360
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,856
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,933
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,249
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,088
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,568
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,227
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
sprintf-js@1.1.3
no fix listed
frinx/frinx-inventory-server:7.0.16b1992c79e78
sprintf-js@1.1.3
no fix listed

Open the chart page →

49,865
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,018
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,271
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,119
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
sprintf-js@1.1.2
no fix listed

Open the chart page →

1,078
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,414
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,391
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,251
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,216
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,889
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
node-sprintf-js@1.1.2+ds1+~1.1.2-1
sprintf-js@1.1.3
no fix listed
no fix listed

Open the chart page →

7,313
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
sprintf-js@1.0.3
no fix listed

Open the chart page →

37,657
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,456
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,333
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,071
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/collector-dynamic:v1.3.06d3d1a5b46a9
sprintf-js@1.1.2
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

26,249
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed

Open the chart page →

56,631
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,651
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,140
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,111
cardinalhbjy0.4.01 of 1See more

cardinal hbjy 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hbjy/cardinal:v1.2.29b80656585cc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,139
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,241
zigbee2mqtthelm-chart-roeiVerified publisher1.19.01 of 1See more

zigbee2mqtt helm-chart-roei 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,258
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
sprintf-js@1.0.3
no fix listed

Open the chart page →

91,741
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,096
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,546
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,195
appwritehelmforgeVerified publisher2.0.31See more

appwrite helmforge 2.0.3

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
appwrite/new:1.1.159-self-hosted1811ce1d8154
sprintf-js@1.0.3
no fix listed

Open the chart page →

—
automatischhelmforgeVerified publisher1.3.91See more

automatisch helmforge 1.3.9

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
sprintf-js@1.0.3
no fix listed

Open the chart page →

—
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
sprintf-js@1.1.3
no fix listed

Open the chart page →

75,877
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,711
dawarichhelmforgeVerified publisher1.0.31See more

dawarich helmforge 1.0.3

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed

Open the chart page →

—
middlewarehelmforgeVerified publisher1.2.81See more

middleware helmforge 1.2.8

1 container image this version deploys carries CVE-2026-97058.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
sprintf-js@1.1.3
no fix listed

Open the chart page →

—
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,604
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,897
webodmhelmforgeVerified publisher1.0.02 of 4See more

webodm helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opendronemap/nodeodm:3.6.2fcd99eb23d8d
sprintf-js@1.0.3
no fix listed
webodm/webodm_webapp:3.3.0ed7b1aa0e40f
sprintf-js@1.0.3
no fix listed

Open the chart page →

22,394
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
sprintf-js@1.0.3
no fix listed

Open the chart page →

25,785
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,609
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,376
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,082

Container images carrying it

584 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
sprintf-js@1.0.3
no fix listed
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
sprintf-js@1.0.3
no fix listed
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
sprintf-js@1.1.3
no fix listed
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sprintf-js@1.1.2
no fix listed
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
sprintf-js@1.0.3
no fix listed
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
sprintf-js@1.0.3
no fix listed
1
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
sprintf-js@1.1.2
no fix listed
1
quay.io/mittwald/kube-mail:latest04f1099241fc
sprintf-js@1.0.3
no fix listed
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
sprintf-js@1.0.3
no fix listed
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
sprintf-js@1.1.3
no fix listed
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
sprintf-js@1.0.3
no fix listed
1
quay.io/seamware/fdsc-dashboard:0.6.63478af70bdc2
sprintf-js@1.1.3
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
sprintf-js@1.1.3
no fix listed
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
sprintf-js@1.1.2
no fix listed
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
sprintf-js@1.0.3
no fix listed
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
sprintf-js@1.1.2
no fix listed
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
sprintf-js@1.0.3
no fix listed
1
quay.io/wekan/wekan:v5.65cb17600883a3
sprintf-js@1.0.3
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
sprintf-js@1.1.3
no fix listed
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.