StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
574
of 18,026 indexed, latest versions
Container images
593
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 574 of 18,026 indexed charts deploy, on 593 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed593
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

574 by stars
ChartLatestAffected imagesRadar Score
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,888
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,826
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,394
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,132
flanksource-uiflanksourceVerified publisher1.4.3211 of 1See more

flanksource-ui flanksource 1.4.321

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.321dcc01382340e
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,263
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,885
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,360
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,856
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,933
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,249
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,088
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,568
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,227
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
sprintf-js@1.1.3
no fix listed
frinx/frinx-inventory-server:7.0.16b1992c79e78
sprintf-js@1.1.3
no fix listed

Open the chart page →

49,865
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,018
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,271
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,119
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
sprintf-js@1.1.2
no fix listed

Open the chart page →

1,078
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,414
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,391
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,251
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,216
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,889
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
node-sprintf-js@1.1.2+ds1+~1.1.2-1
sprintf-js@1.1.3
no fix listed
no fix listed

Open the chart page →

7,313
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
sprintf-js@1.0.3
no fix listed

Open the chart page →

37,657
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,456
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,333
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,071
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/collector-dynamic:v1.3.06d3d1a5b46a9
sprintf-js@1.1.2
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

26,249
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed

Open the chart page →

56,631
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,651
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,140
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,111
cardinalhbjy0.4.01 of 1See more

cardinal hbjy 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hbjy/cardinal:v1.2.29b80656585cc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,139
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,241
zigbee2mqtthelm-chart-roeiVerified publisher1.19.01 of 1See more

zigbee2mqtt helm-chart-roei 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,258
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
sprintf-js@1.0.3
no fix listed

Open the chart page →

91,741
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,096
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,546
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,195
appwritehelmforgeVerified publisher2.0.21 of 5See more

appwrite helmforge 2.0.2

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
appwrite/new:1.1.159-self-hosted1811ce1d8154
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,228
automatischhelmforgeVerified publisher1.3.81 of 4See more

automatisch helmforge 1.3.8

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,479
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
sprintf-js@1.1.3
no fix listed

Open the chart page →

75,877
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,711
dawarichhelmforgeVerified publisher1.0.21 of 4See more

dawarich helmforge 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed

Open the chart page →

12,097
middlewarehelmforgeVerified publisher1.2.71 of 4See more

middleware helmforge 1.2.7

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,528
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,604
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,897

Container images carrying it

593 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
requarks/wiki:latestfffff288a52f
sprintf-js@1.0.3
no fix listed
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
sprintf-js@1.0.3
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
sprintf-js@1.1.3
no fix listed
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
sprintf-js@1.0.3
no fix listed
2
statsd/statsd:v0.8.6dab129e74c25
sprintf-js@1.0.3
no fix listed
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
sprintf-js@1.1.3
no fix listed
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
sprintf-js@1.1.2
no fix listed
2
temporalio/web:1.14.033cfa863d8ce
sprintf-js@1.0.3
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
sprintf-js@1.1.2
no fix listed
2
ubercadence/web:v3.29.58564a5b44a6d
sprintf-js@1.0.3
no fix listed
2
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sprintf-js@1.1.3
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
sprintf-js@1.1.3
no fix listed
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
sprintf-js@1.1.3
no fix listed
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
sprintf-js@1.0.3
no fix listed
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
sprintf-js@1.1.3
no fix listed
2
ghcr.io/seerr-team/seerr:latest:v3.5.027602401178d
sprintf-js@1.1.3
no fix listed
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
sprintf-js@1.1.3
no fix listed
2
activepieces/activepieces:0.91.058414dfc94c4
sprintf-js@1.0.3
no fix listed
1
activepieces/activepieces:0.28.0a12efde0c535
sprintf-js@1.1.3
no fix listed
1
activepieces/activepieces:0.23.0c26188b44e62
sprintf-js@1.1.3
no fix listed
1
actualbudget/actual-server:25.3.158fecd9088b7
sprintf-js@1.1.3
no fix listed
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
sprintf-js@1.1.3
no fix listed
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
sprintf-js@1.1.3
no fix listed
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
sprintf-js@1.1.3
no fix listed
1
alazidis/stornx:1.1.1602d4f7f090c
sprintf-js@1.1.3
no fix listed
1
alquimiaai/studio:certification38a1f0341982
sprintf-js@1.1.3
no fix listed
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
sprintf-js@1.0.3
no fix listed
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
sprintf-js@1.0.3
no fix listed
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
sprintf-js@1.1.3
no fix listed
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
sprintf-js@1.1.3
no fix listed
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
sprintf-js@1.1.3
no fix listed
1
appwrite/new:1.1.159-self-hosted1811ce1d8154
sprintf-js@1.0.3
no fix listed
1
arbuzov/claude-code-api:0.1.02d7dd8070610
sprintf-js@1.1.3
no fix listed
1
arfath29/3-tier-app-frontend:latest384b3e377f47
sprintf-js@1.0.3
no fix listed
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
sprintf-js@1.0.3
no fix listed
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
sprintf-js@1.0.3
no fix listed
1
assistiot/fl_orchestrator:api-latest7473d77448e1
sprintf-js@1.0.3
no fix listed
1
assistiot/open_api_frontend:1.0.1f11d82defc70
sprintf-js@1.0.3
no fix listed
1
automatischio/automatisch:0.15.03bace7a12d5f
sprintf-js@1.0.3
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
sprintf-js@1.0.3
no fix listed
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
sprintf-js@1.1.2
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
sprintf-js@1.1.3
no fix listed
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
sprintf-js@1.0.3
no fix listed
1
bluerange/bluerange-mosquitto:2690a4e5b92cc6
sprintf-js@1.0.3
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
sprintf-js@1.1.3
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
sprintf-js@1.0.3
no fix listed
1
budibase/apps:3.41.344fe6feab985
sprintf-js@1.0.3
no fix listed
1
budibase/worker:3.41.3de5e2e560ce8
sprintf-js@1.1.3
no fix listed
1
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
node-sprintf-js@1.1.2+ds1+~1.1.2-1
sprintf-js@1.1.3
no fix listed
no fix listed
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
sprintf-js@1.0.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.