StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
565
of 18,035 indexed, latest versions
Container images
584
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 565 of 18,035 indexed charts deploy, on 584 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed584
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

565 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
sprintf-js@1.1.2
no fix listed

Open the chart page →

7,239
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
sprintf-js@1.0.3
no fix listed

Open the chart page →

15,162
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
sprintf-js@1.0.3
no fix listed

Open the chart page →

30,229
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,651
cadencewener0.23.01 of 5See more

cadence wener 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
sprintf-js@1.0.3
no fix listed

Open the chart page →

13,179
temporalwener0.15.11 of 13See more

temporal wener 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
sprintf-js@1.0.3
no fix listed

Open the chart page →

29,471
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
requarks/wiki:latestfffff288a52f
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,599
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
sprintf-js@1.0.3
no fix listed

Open the chart page →

13,179
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
sprintf-js@1.0.3
no fix listed

Open the chart page →

29,471
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,321
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,098
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,686
workadventure-adminwork-adventure1.0.0-21-31 of 14See more

workadventure-admin work-adventure 1.0.0-21-3

1 of the 14 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:helm-chart519c31c6e7ec
sprintf-js@1.0.3
no fix listed

Open the chart page →

19,835
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
sprintf-js@1.0.3
no fix listed

Open the chart page →

20,456
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
sprintf-js@1.1.2
no fix listed

Open the chart page →

12,360

Container images carrying it

584 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ltdstudio/terraforming-mars:latest0e76c6f4eac0
sprintf-js@1.0.3
no fix listed
1
lucassandin/welcome-client:latest48468b1ccd16
sprintf-js@1.1.3
no fix listed
1
luligu/matterbridge:3.0.28f97884bebc2
sprintf-js@1.1.3
no fix listed
1
lyzhang1999/frontend:latest4b25cf264fd7
sprintf-js@1.0.3
no fix listed
1
maildev/maildev:2.2.1180ef51f65ee
sprintf-js@1.1.3
no fix listed
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
sprintf-js@1.0.3
no fix listed
1
mauricenino/dashdot:5.9.2236997816917
sprintf-js@1.1.3
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
sprintf-js@1.0.3
no fix listed
1
mcp/kubernetes:latest5ffbf7f0a8aa
sprintf-js@1.1.3
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
sprintf-js@1.1.3
no fix listed
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
sprintf-js@1.0.3
no fix listed
1
mishtinetwork/operator:latestbb3fe67a5f7c
sprintf-js@1.1.3
no fix listed
1
misskey/misskey:12.110.1e08b7c478093
sprintf-js@1.0.3
no fix listed
1
mitchxxx/amazon:214e72480ec63a
sprintf-js@1.0.3
no fix listed
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
sprintf-js@1.1.3
no fix listed
1
moreillon/api-proxy:2373c1953739ef6956b5
sprintf-js@1.0.3
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
sprintf-js@1.1.3
no fix listed
1
moreillon/camera-proxy:latestce60056b50c2
sprintf-js@1.1.3
no fix listed
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
sprintf-js@1.0.3
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
sprintf-js@1.1.3
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
sprintf-js@1.1.3
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
sprintf-js@1.0.3
no fix listed
1
mozilla/sentencecollector:2.0.91da6ff5c4895
sprintf-js@1.0.3
no fix listed
1
n8nio/n8n:2.25.7761374d4eb84
sprintf-js@1.0.3
no fix listed
1
n8nio/n8n:2.41.687e0bab2c931
sprintf-js@1.0.3
no fix listed
1
n8nio/n8n:1.86.08b39ed5a2de9
sprintf-js@1.1.3
no fix listed
1
n8nio/n8n:0.212.0a9195bc499a3
sprintf-js@1.1.2
no fix listed
1
n8nio/n8n:2.36.8cfe2704ff858
sprintf-js@1.1.3
no fix listed
1
n8nio/n8n:1.33.1dd171d45102a
sprintf-js@1.1.3
no fix listed
1
n8nio/n8n:0.136.0e8302e8bd402
sprintf-js@1.1.2
no fix listed
1
n8nio/n8n:1.115.1ed16e560c40e
sprintf-js@1.1.3
no fix listed
1
n8nio/n8n:2.41.3fdce8f852ac7
sprintf-js@1.1.3
no fix listed
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
sprintf-js@1.0.3
no fix listed
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
sprintf-js@1.0.3
no fix listed
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
sprintf-js@1.0.3
no fix listed
1
nocodb/nocodb:latest4ccfc5114506
sprintf-js@1.1.3
no fix listed
1
nocodb/nocodb:0.258.06779a4ddedf2
sprintf-js@1.1.3
no fix listed
1
nocodb/nocodb:0.301.5d9516f0bf546
sprintf-js@1.1.3
no fix listed
1
nodered/node-red:4.1.2216e7403aab9
sprintf-js@1.1.3
no fix listed
1
nodered/node-red:4.1.10-minimald73ae167cb9b
sprintf-js@1.1.3
no fix listed
1
nodered/node-red:2.2.2e131dcadfe92
sprintf-js@1.0.3
no fix listed
1
nodered/node-red-docker:0.19.6-v8070643219ea2
sprintf-js@1.0.3
no fix listed
1
nshou/elasticsearch-kibana:kibana7a1d1e36814d1
sprintf-js@1.0.3
no fix listed
1
oada/auth:4.0.0c0d077e79ef4
sprintf-js@1.1.3
no fix listed
1
oada/http-handler:4.0.0d87efe8ba4b0
sprintf-js@1.1.3
no fix listed
1
oada/rev-graph-update:4.0.0ebc8343f05ff
sprintf-js@1.1.3
no fix listed
1
oada/shares:4.0.0c6ffb4e8ed63
sprintf-js@1.1.3
no fix listed
1
oada/startup:4.0.0fc09495e2f3c
sprintf-js@1.1.3
no fix listed
1
oada/sync-handler:4.0.0b7a2cfc137cf
sprintf-js@1.1.3
no fix listed
1
oada/users:4.0.0b6c562fa5b1b
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.