StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 18,035 indexed, latest versions
Container images
585
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 567 of 18,035 indexed charts deploy, on 585 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed585
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed

Open the chart page →

37,502
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,671
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sprintf-js@1.1.3
no fix listed

Open the chart page →

41,499
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,160
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed

Open the chart page →

37,502
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,818
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
sprintf-js@1.1.3
no fix listed
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,882
efklovemew67Verified publisher0.0.11 of 2See more

efk lovemew67 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nshou/elasticsearch-kibana:kibana7a1d1e36814d1
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,456
mongo_guilovemew67Verified publisher0.0.21 of 1See more

mongo_gui lovemew67 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.1.1e3952b14ae8e
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,247
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,165
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,336
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,814
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,158
homepagem0sh1-helm-charts0.3.11 of 1See more

homepage m0sh1-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.11.0b129cb0f674b
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,976
wudm0sh1-helm-charts0.2.01 of 1See more

wud m0sh1-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
getwud/wud:8.1.1b1cd01c43839
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,829
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
sprintf-js@1.1.3
no fix listed

Open the chart page →

31,422
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
sprintf-js@1.1.3
no fix listed

Open the chart page →

13,747
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,534
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,458
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,654
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,120
claude-code-apimcp-helmVerified publisher0.1.11 of 1See more

claude-code-api mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
arbuzov/claude-code-api:0.1.02d7dd8070610
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,685
mcp-gitlabmcp-helmVerified publisher0.3.41 of 1See more

mcp-gitlab mcp-helm 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,296
mcp-kubernetesmcp-helmVerified publisher0.2.71 of 1See more

mcp-kubernetes mcp-helm 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mcp/kubernetes:latest5ffbf7f0a8aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,466
mcpomcp-helmVerified publisher0.2.81 of 1See more

mcpo mcp-helm 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,933
mcp-playwrightmcp-helmVerified publisher0.1.11 of 1See more

mcp-playwright mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,652
searchmcp-helmVerified publisher0.1.31 of 2See more

search mcp-helm 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
laituanmanh/websearch-crawler:latest63b6da557c71
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,796
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,864
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed

Open the chart page →

88,945
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,572
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,032
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
sprintf-js@1.0.3
no fix listed

Open the chart page →

116,577
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,077
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed

Open the chart page →

11,596
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,743
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,743
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

13,164
finance-portalmojaloop5.1.46 of 11See more

finance-portal mojaloop 5.1.4

6 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed

Open the chart page →

16,967
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,263
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed

Open the chart page →

20,648
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,161
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,019
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,852
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,922
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,334
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,554
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,851
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,148
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,155
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,072

Container images carrying it

585 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
vcnngr/pnbackend:latesteaf44ad0ad1f
sprintf-js@1.1.3
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
sprintf-js@1.1.3
no fix listed
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
sprintf-js@1.1.3
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
sprintf-js@1.0.3
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
sprintf-js@1.0.3
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
sprintf-js@1.0.3
no fix listed
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
sprintf-js@1.1.2
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
sprintf-js@1.1.2
no fix listed
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
sprintf-js@1.1.2
no fix listed
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
sprintf-js@1.1.2
no fix listed
1
webodm/webodm_webapp:3.3.0ed7b1aa0e40f
sprintf-js@1.0.3
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
sprintf-js@1.0.3
no fix listed
1
wettyoss/wetty:latestc52dac712353
sprintf-js@1.1.3
no fix listed
1
willwill/kube-slack:v4.1.1d443017aae98
sprintf-js@1.0.3
no fix listed
1
winfred008/amazon:910a68de5b398
sprintf-js@1.0.3
no fix listed
1
wiremind/scrapoxy:lateste7048929a676
sprintf-js@1.0.3
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sprintf-js@1.1.3
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
sprintf-js@1.1.3
no fix listed
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
sprintf-js@1.1.3
no fix listed
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
sprintf-js@1.1.3
no fix listed
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
sprintf-js@1.1.3
no fix listed
1
zazuko/trifid:2.3.7054be137de70
sprintf-js@1.0.3
no fix listed
1
zimengxiong/excalidash-backend:0.4.271273af713c91
sprintf-js@1.1.3
no fix listed
1
zimengxiong/excalidash-backend:0.6.529937c62fbed
sprintf-js@1.1.3
no fix listed
1
zooz/predator:1.6f491d1f7a865
sprintf-js@1.1.2
no fix listed
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
sprintf-js@1.0.3
no fix listed
1
zwavejs/zwave-js-ui:11.24.2717f9d260902
sprintf-js@1.1.3
no fix listed
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
sprintf-js@1.1.3
no fix listed
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
sprintf-js@1.0.3
no fix listed
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/console-api:2.64.0ba359097329d
sprintf-js@1.0.3
no fix listed
1
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/provider-console-security:1.0.0b87a48ec51dd
sprintf-js@1.1.3
no fix listed
1
ghcr.io/akash-network/provider-proxy:1.4.353f533d7c6f8
sprintf-js@1.0.3
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
sprintf-js@1.1.3
no fix listed
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
sprintf-js@1.1.3
no fix listed
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
sprintf-js@1.1.3
no fix listed
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
sprintf-js@1.1.3
no fix listed
1
ghcr.io/backstage/backstage:lateste2a48bb6ab55
sprintf-js@1.0.3
no fix listed
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
sprintf-js@1.1.3
no fix listed
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
sprintf-js@1.1.3
no fix listed
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
sprintf-js@1.1.3
no fix listed
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.