StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
574
of 18,026 indexed, latest versions
Container images
593
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 574 of 18,026 indexed charts deploy, on 593 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed593
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

574 by stars
ChartLatestAffected imagesRadar Score
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
sprintf-js@1.1.3
no fix listed

Open the chart page →

9,745
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,990
community-solid-servercommunity-solid-server3.0.01 of 1See more

community-solid-server community-solid-server 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
solidproject/community-server:6.0.2ccc4acb7e9a1
sprintf-js@1.0.3
no fix listed

Open the chart page →

1,819
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,612
convertigoconvertigoOfficialVerified publisher8.4.51 of 5See more

convertigo convertigo 8.4.5

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
sprintf-js@1.0.3
no fix listed

Open the chart page →

17,283
cosmocosmo-platformOfficialVerified publisher0.20.03 of 10See more

cosmo cosmo-platform 0.20.0

3 of the 10 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
sprintf-js@1.1.3
no fix listed
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
sprintf-js@1.1.3
no fix listed
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
sprintf-js@1.1.3
no fix listed

Open the chart page →

34,276
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,703
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,195
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,762
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,161
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,345
kubeviouskubevious1.2.23 of 7See more

kubevious kubevious 1.2.2

3 of the 7 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kubevious/collector:1.2.1f58226f9d84e
sprintf-js@1.0.3
no fix listed
kubevious/guard:1.2.19bf567704de2
sprintf-js@1.0.3
no fix listed
kubevious/parser:1.2.299ae7a5168c2
sprintf-js@1.0.3
no fix listed

Open the chart page →

17,557
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,450
mstreamnicholaswildeVerified publisher2.1.21 of 1See more

mstream nicholaswilde 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mstream:version-v5.2.522c012bcc43c
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,643
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
sprintf-js@1.0.3
no fix listed

Open the chart page →

7,851
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
sprintf-js@1.0.3
no fix listed
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sprintf-js@1.0.3
no fix listed

Open the chart page →

23,691
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
sprintf-js@1.1.2
no fix listed

Open the chart page →

8,503
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,992
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sprintf-js@1.0.3
no fix listed

Open the chart page →

1,450
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
sprintf-js@1.0.3
no fix listed

Open the chart page →

102,426
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
sprintf-js@1.1.2
no fix listed

Open the chart page →

1,891
feedbacksystemthm-mni-iiVerified publisher0.48.12 of 14See more

feedbacksystem thm-mni-ii 0.48.1

2 of the 14 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/thm-mni-ii/fbs-qcm-backend:v2.0.6f1a7afffedab
sprintf-js@1.1.3
no fix listed
ghcr.io/thm-mni-ii/fbs-qcm-frontend:v2.0.6fc8ab4ce0654
sprintf-js@1.1.3
no fix listed

Open the chart page →

29,135
wgerwgerOfficialVerified publisher2.0.01 of 7See more

wger wger 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latest413a0c813e96
sprintf-js@1.1.3
no fix listed

Open the chart page →

8,934
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,210
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
sprintf-js@1.1.2
no fix listed

Open the chart page →

3,168
dbgateappscodeVerified publisher2026.3.301 of 1See more

dbgate appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.0-alpine287077002446
sprintf-js@1.1.3
no fix listed

Open the chart page →

942
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
sprintf-js@1.0.3
no fix listed

Open the chart page →

20,196
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,246
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,452
pysequilabiodatageeks0.1.31 of 7See more

pysequila biodatageeks 0.1.3

1 of the 7 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.2.1b328f93ad125
sprintf-js@1.0.3
no fix listed

Open the chart page →

87,922
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,045
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,591
dawarichcogitriVerified publisher2.9.21 of 3See more

dawarich cogitri 2.9.2

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,974
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
sprintf-js@1.1.3
no fix listed
ghcr.io/data-fair/metrics:0a8d40779eeae
sprintf-js@1.0.3
no fix listed
ghcr.io/data-fair/notify:3c739b74dabb0
sprintf-js@1.0.3
no fix listed
ghcr.io/data-fair/portals:18b621866ceb2
sprintf-js@1.0.3
no fix listed
ghcr.io/data-fair/processings:15a9216989707
sprintf-js@1.0.3
no fix listed
ghcr.io/data-fair/simple-directory:438a4f32fad82
sprintf-js@1.0.3
no fix listed

Open the chart page →

42,584
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
sprintf-js@1.0.3
no fix listed

Open the chart page →

5,735
matomodigitalist-open-cloud-matomo12.0.211 of 3See more

matomo digitalist-open-cloud-matomo 12.0.21

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
digitalist/matomo:5.12.0bc4aeeaea769
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,495
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
sprintf-js@1.1.2
no fix listed

Open the chart page →

9,353
joplin-serverdjjudas21Verified publisher6.0.01 of 1See more

joplin-server djjudas21 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
joplin/server:3.7.23f7b852959aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,964
domain-lockerdomain-locker0.3.11 of 2See more

domain-locker domain-locker 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lissy93/domain-locker:latest58a903b2cdd9
sprintf-js@1.0.3
no fix listed

Open the chart page →

1,035
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
sprintf-js@1.1.3
no fix listed

Open the chart page →

75,225
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
sprintf-js@1.0.3
no fix listed
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
sprintf-js@1.0.3
no fix listed
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
sprintf-js@1.0.3
no fix listed

Open the chart page →

35,965
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,103
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
sprintf-js@1.1.3
no fix listed

Open the chart page →

13,128
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
sprintf-js@1.1.2
no fix listed

Open the chart page →

2,660
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
sprintf-js@1.1.2
no fix listed

Open the chart page →

5,717
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
sprintf-js@1.1.2
no fix listed

Open the chart page →

3,650
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,710
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
sprintf-js@1.1.2
no fix listed

Open the chart page →

6,582
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,258
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,623

Container images carrying it

593 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
5
decisionrules/server:latestbb3a93224b5a
sprintf-js@1.1.3
no fix listed
4
redis/redisinsight:3.8:latestb5e19ee240ab
sprintf-js@1.1.3
no fix listed
4
joplin/server:3.7.2:latest3f7b852959aa
sprintf-js@1.1.3
no fix listed
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
3
pantsel/konga:latestc8172b75607d
sprintf-js@1.0.3
no fix listed
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
sprintf-js@1.0.3
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
sprintf-js@1.0.3
no fix listed
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sprintf-js@1.0.3
no fix listed
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
sprintf-js@1.0.3
no fix listed
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
sprintf-js@1.0.3
no fix listed
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
sprintf-js@1.0.3
no fix listed
2
epamedp/krci-portal:0.8.0687acf641097
sprintf-js@1.1.3
no fix listed
2
etherpad/etherpad:3.3.6:latest98d395769b3b
sprintf-js@1.0.3
no fix listed
2
ethersphere/bee-localchain:latest0558799ca992
sprintf-js@1.0.3
no fix listed
2
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
sprintf-js@1.0.3
no fix listed
2
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
2
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
2
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
2
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
2
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
sprintf-js@1.0.3
no fix listed
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed
2
library/arangodb:3.11.81e75d74954a4
sprintf-js@1.0.3
no fix listed
2
library/mongo-express:1.0.2:latest1b23d7976f02
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:1.23.1396510915e6be
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
sprintf-js@1.1.3
no fix listed
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
sprintf-js@1.0.3
no fix listed
2
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed
2
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
sprintf-js@1.0.3
no fix listed
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
sprintf-js@1.0.3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
sprintf-js@1.0.3
no fix listed
2
n8nio/n8n:2.36.714c4285bc303
sprintf-js@1.0.3
no fix listed
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed
2
outlinewiki/outline:0.69.1d060dcd8f9aa
sprintf-js@1.0.3
no fix listed
2
rajnandan1/kener:3.2.1930407afca731
sprintf-js@1.1.3
no fix listed
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
sprintf-js@1.1.3
no fix listed
2

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.