StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
565
of 18,035 indexed, latest versions
Container images
584
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 565 of 18,035 indexed charts deploy, on 584 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed584
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

565 by stars
ChartLatestAffected imagesRadar Score
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
sprintf-js@1.0.3
no fix listed
ibmcom/app-nav-ui:1.0.1e2a86997b36b
sprintf-js@1.0.3
no fix listed

Open the chart page →

33,453
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
sprintf-js@1.0.3
no fix listed

Open the chart page →

40,065
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
sprintf-js@1.0.3
no fix listed

Open the chart page →

119,072
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,683
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
sprintf-js@1.1.3
no fix listed

Open the chart page →

12,896
indexer-chartindexer-application0.1.01 of 1See more

indexer-chart indexer-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ibarreche/cloud-indexer-ci:latestb7a08274e69f
sprintf-js@1.1.2
no fix listed

Open the chart page →

3,662
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,783
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,166
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4ccfc5114506
sprintf-js@1.1.3
no fix listed

Open the chart page →

873
interbtc-hydrainterlay0.1.151 of 4See more

interbtc-hydra interlay 0.1.15

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
sprintf-js@1.0.3
no fix listed

Open the chart page →

7,783
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,604
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,517
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,063
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,065
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,924
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,752
image-storage-servicejtektVerified publisher0.5.11 of 4See more

image-storage-service jtekt 0.5.1

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
sprintf-js@1.1.3
no fix listed

Open the chart page →

24,912
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,652
shinsei-managerjtektVerified publisher0.2.04 of 8See more

shinsei-manager jtekt 0.2.0

4 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
sprintf-js@1.1.3
no fix listed
moreillon/group-manager:latest3caa8f710ee0
sprintf-js@1.1.3
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
sprintf-js@1.0.3
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
sprintf-js@1.1.3
no fix listed

Open the chart page →

68,829
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
sprintf-js@1.0.3
no fix listed

Open the chart page →

18,504
docker-hub-rssjuniorjpdj0.1.331 of 1See more

docker-hub-rss juniorjpdj 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,166
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
sprintf-js@1.0.3
no fix listed

Open the chart page →

1,680
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,955
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
sprintf-js@1.1.3
no fix listed

Open the chart page →

73,425
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,647
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,012
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
sprintf-js@1.1.2
no fix listed

Open the chart page →

10,814
zwave-js-uik8sonlabVerified publisher0.7.141 of 1See more

zwave-js-ui k8sonlab 0.7.14

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.24.2717f9d260902
sprintf-js@1.1.3
no fix listed

Open the chart page →

825
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,173
keycloak-multi-client-notifierkeycloak-multi-client-notifier2.1.21 of 2See more

keycloak-multi-client-notifier keycloak-multi-client-notifier 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,973
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,503
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,809
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
sprintf-js@1.1.3
no fix listed

Open the chart page →

9,922
deployment-servicekrateo1.2.591 of 1See more

deployment-service krateo 1.2.59

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/deployment-service:1.2.59da9f93f2f731
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,241
terminal-clientkrateo0.1.31 of 1See more

terminal-client krateo 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/terminal-client:0.1.36c7c965e739c
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,302
terminal-serverkrateo0.1.61 of 1See more

terminal-server krateo 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/krateoplatformops/terminal-server:0.1.3f5fd8ba6fea3
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,241
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
sprintf-js@1.1.2
no fix listed

Open the chart page →

3,611
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,745
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
sprintf-js@1.1.3
no fix listed

Open the chart page →

9,493
gptchat-api-feishubotkubegemsapp0.1.11 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kubegems/chatgpt-api:latestf3c492a938ad
sprintf-js@1.0.3
no fix listed

Open the chart page →

11,475
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,000
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,668
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,904
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,087
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
sprintf-js@1.1.3
no fix listed

Open the chart page →

19,014
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
sprintf-js@1.1.3
no fix listed

Open the chart page →

24,542
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,883
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,268
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,948
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed

Open the chart page →

37,502

Container images carrying it

584 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
sprintf-js@1.0.3
no fix listed
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
sprintf-js@1.1.3
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
sprintf-js@1.0.3
no fix listed
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
sprintf-js@1.1.3
no fix listed
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sprintf-js@1.1.2
no fix listed
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
sprintf-js@1.0.3
no fix listed
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
sprintf-js@1.0.3
no fix listed
1
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
sprintf-js@1.1.2
no fix listed
1
quay.io/mittwald/kube-mail:latest04f1099241fc
sprintf-js@1.0.3
no fix listed
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
sprintf-js@1.0.3
no fix listed
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
sprintf-js@1.1.3
no fix listed
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
sprintf-js@1.0.3
no fix listed
1
quay.io/seamware/fdsc-dashboard:0.6.63478af70bdc2
sprintf-js@1.1.3
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
sprintf-js@1.1.3
no fix listed
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
sprintf-js@1.1.2
no fix listed
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
sprintf-js@1.0.3
no fix listed
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
sprintf-js@1.1.2
no fix listed
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
sprintf-js@1.0.3
no fix listed
1
quay.io/wekan/wekan:v5.65cb17600883a3
sprintf-js@1.0.3
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
sprintf-js@1.1.3
no fix listed
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
sprintf-js@1.1.3
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
sprintf-js@1.0.3
no fix listed
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.