StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
574
of 18,026 indexed, latest versions
Container images
593
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 574 of 18,026 indexed charts deploy, on 593 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed593
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

574 by stars
ChartLatestAffected imagesRadar Score
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,888
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,826
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,394
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,132
flanksource-uiflanksourceVerified publisher1.4.3211 of 1See more

flanksource-ui flanksource 1.4.321

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.321dcc01382340e
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,263
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,885
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,360
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,856
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,933
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,249
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,088
uptime-kumafossa1.0.11 of 1See more

uptime-kuma fossa 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/k3rnel-pan1c/uptime-kuma:1.19.3f975fde9329b
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,568
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,227
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
sprintf-js@1.1.3
no fix listed
frinx/frinx-inventory-server:7.0.16b1992c79e78
sprintf-js@1.1.3
no fix listed

Open the chart page →

49,865
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,018
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,271
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,119
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
sprintf-js@1.1.2
no fix listed

Open the chart page →

1,078
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,414
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,391
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,251
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,216
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,101
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,889
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
node-sprintf-js@1.1.2+ds1+~1.1.2-1
sprintf-js@1.1.3
no fix listed
no fix listed

Open the chart page →

7,313
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
sprintf-js@1.0.3
no fix listed

Open the chart page →

37,657
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,456
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
sprintf-js@1.1.3
no fix listed

Open the chart page →

15,333
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

24,071
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
governify/collector-dynamic:v1.3.06d3d1a5b46a9
sprintf-js@1.1.2
no fix listed
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed

Open the chart page →

26,249
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
sprintf-js@1.1.3
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
sprintf-js@1.1.3
no fix listed

Open the chart page →

56,631
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,651
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,140
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,111
cardinalhbjy0.4.01 of 1See more

cardinal hbjy 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hbjy/cardinal:v1.2.29b80656585cc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,139
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,241
zigbee2mqtthelm-chart-roeiVerified publisher1.19.01 of 1See more

zigbee2mqtt helm-chart-roei 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,258
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
sprintf-js@1.0.3
no fix listed
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
sprintf-js@1.0.3
no fix listed

Open the chart page →

91,741
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,096
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,546
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,195
appwritehelmforgeVerified publisher2.0.21 of 5See more

appwrite helmforge 2.0.2

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
appwrite/new:1.1.159-self-hosted1811ce1d8154
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,228
automatischhelmforgeVerified publisher1.3.81 of 4See more

automatisch helmforge 1.3.8

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,479
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
sprintf-js@1.1.3
no fix listed

Open the chart page →

75,877
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,711
dawarichhelmforgeVerified publisher1.0.21 of 4See more

dawarich helmforge 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed

Open the chart page →

12,097
middlewarehelmforgeVerified publisher1.2.71 of 4See more

middleware helmforge 1.2.7

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,528
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,604
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,897

Container images carrying it

593 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
vabene1111/recipes:2.3.50f8d061895e9
sprintf-js@1.1.3
no fix listed
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sprintf-js@1.0.3
no fix listed
1
vcnngr/pnbackend:latesteaf44ad0ad1f
sprintf-js@1.1.3
no fix listed
1
veecode/devportal881f936ff4a3
sprintf-js@1.1.3
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
sprintf-js@1.1.3
no fix listed
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
sprintf-js@1.1.3
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
sprintf-js@1.0.3
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
sprintf-js@1.0.3
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
sprintf-js@1.0.3
no fix listed
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
sprintf-js@1.1.2
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
sprintf-js@1.1.2
no fix listed
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
sprintf-js@1.1.2
no fix listed
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
sprintf-js@1.1.2
no fix listed
1
webodm/webodm_webapp:3.3.0ed7b1aa0e40f
sprintf-js@1.0.3
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
sprintf-js@1.0.3
no fix listed
1
wettyoss/wetty:latestc52dac712353
sprintf-js@1.1.3
no fix listed
1
willwill/kube-slack:v4.1.1d443017aae98
sprintf-js@1.0.3
no fix listed
1
winfred008/amazon:910a68de5b398
sprintf-js@1.0.3
no fix listed
1
wiremind/scrapoxy:lateste7048929a676
sprintf-js@1.0.3
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sprintf-js@1.1.3
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
sprintf-js@1.1.3
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
sprintf-js@1.1.3
no fix listed
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
sprintf-js@1.1.3
no fix listed
1
zazuko/trifid:2.3.7054be137de70
sprintf-js@1.0.3
no fix listed
1
zimengxiong/excalidash-backend:0.4.271273af713c91
sprintf-js@1.1.3
no fix listed
1
zimengxiong/excalidash-backend:0.6.529937c62fbed
sprintf-js@1.1.3
no fix listed
1
zooz/predator:1.6f491d1f7a865
sprintf-js@1.1.2
no fix listed
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
sprintf-js@1.0.3
no fix listed
1
zwavejs/zwave-js-ui:11.24.2717f9d260902
sprintf-js@1.1.3
no fix listed
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
sprintf-js@1.1.3
no fix listed
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
sprintf-js@1.0.3
no fix listed
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/console-api:2.64.0ba359097329d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/provider-console-security:1.0.0b87a48ec51dd
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/provider-proxy:1.4.353f533d7c6f8
sprintf-js@1.0.3
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
sprintf-js@1.1.3
no fix listed
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
sprintf-js@1.1.3
no fix listed
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
sprintf-js@1.1.3
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
sprintf-js@1.1.3
no fix listed
1
ghcr.io/backstage/backstage:lateste2a48bb6ab55
sprintf-js@1.0.3
no fix listed
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.