StackRadar

CVE-2026-97058

Medium

Advisory

Published 24 Sept 2026In the index since 25 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
574
of 18,026 indexed, latest versions
Container images
593
deployed by those charts
Fix available
None
affected packages

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Carried by container images the latest versions of 574 of 18,026 indexed charts deploy, on 593 images.

Affected packageAffected versionsFixed inImages
sprintf-jsnpm1.0.3, 1.1.1, 1.1.2, 1.1.3no fix listed593
node-sprintf-jsdeb1.1.2+ds1+~1.1.2-1no fix listed2
OSV records
GHSA-hp3w-g68c-fv3cUBUNTU-CVE-2026-97058

Charts affected

574 by stars
ChartLatestAffected imagesRadar Score
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
sprintf-js@1.1.3
no fix listed

Open the chart page →

19,014
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
sprintf-js@1.1.3
no fix listed

Open the chart page →

24,542
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,883
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,268
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,948
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed

Open the chart page →

37,502
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,671
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
sprintf-js@1.1.3
no fix listed

Open the chart page →

41,499
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,160
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed

Open the chart page →

37,502
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,818
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
sprintf-js@1.1.3
no fix listed
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
sprintf-js@1.1.3
no fix listed

Open the chart page →

3,882
efklovemew67Verified publisher0.0.11 of 2See more

efk lovemew67 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
nshou/elasticsearch-kibana:kibana7a1d1e36814d1
sprintf-js@1.0.3
no fix listed

Open the chart page →

4,456
mongo_guilovemew67Verified publisher0.0.21 of 1See more

mongo_gui lovemew67 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.1.1e3952b14ae8e
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,247
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,165
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,336
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,814
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
sprintf-js@1.1.3
no fix listed

Open the chart page →

5,158
homepagem0sh1-helm-charts0.3.11 of 1See more

homepage m0sh1-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.11.0b129cb0f674b
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,976
wudm0sh1-helm-charts0.2.01 of 1See more

wud m0sh1-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
getwud/wud:8.1.1b1cd01c43839
sprintf-js@1.1.3
no fix listed

Open the chart page →

7,829
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
sprintf-js@1.1.3
no fix listed

Open the chart page →

31,422
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
sprintf-js@1.1.3
no fix listed

Open the chart page →

13,747
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,534
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,458
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
sprintf-js@1.0.3
no fix listed

Open the chart page →

9,654
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
sprintf-js@1.0.3
no fix listed

Open the chart page →

6,120
claude-code-apimcp-helmVerified publisher0.1.11 of 1See more

claude-code-api mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
arbuzov/claude-code-api:0.1.02d7dd8070610
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,685
mcp-gitlabmcp-helmVerified publisher0.3.41 of 1See more

mcp-gitlab mcp-helm 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,296
mcp-kubernetesmcp-helmVerified publisher0.2.71 of 1See more

mcp-kubernetes mcp-helm 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mcp/kubernetes:latest5ffbf7f0a8aa
sprintf-js@1.1.3
no fix listed

Open the chart page →

6,466
mcpomcp-helmVerified publisher0.2.81 of 1See more

mcpo mcp-helm 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,933
mcp-playwrightmcp-helmVerified publisher0.1.11 of 1See more

mcp-playwright mcp-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
sprintf-js@1.1.3
no fix listed

Open the chart page →

4,652
searchmcp-helmVerified publisher0.1.31 of 2See more

search mcp-helm 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
laituanmanh/websearch-crawler:latest63b6da557c71
sprintf-js@1.1.3
no fix listed

Open the chart page →

10,796
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
sprintf-js@1.0.3
no fix listed

Open the chart page →

10,864
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed

Open the chart page →

88,945
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed

Open the chart page →

8,572
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
sprintf-js@1.1.3
no fix listed

Open the chart page →

14,032
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
sprintf-js@1.0.3
no fix listed

Open the chart page →

116,577
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,077
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed

Open the chart page →

11,596
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,743
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,743
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed

Open the chart page →

13,164
finance-portalmojaloop5.1.46 of 11See more

finance-portal mojaloop 5.1.4

6 of the 11 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed

Open the chart page →

16,967
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed

Open the chart page →

12,263
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed

Open the chart page →

20,648
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,161
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed

Open the chart page →

3,019
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed

Open the chart page →

1,852
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed

Open the chart page →

2,922
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-97058.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed

Open the chart page →

2,334

Container images carrying it

593 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
sprintf-js@1.0.3
no fix listed
5
decisionrules/server:latestbb3a93224b5a
sprintf-js@1.1.3
no fix listed
4
redis/redisinsight:3.8:latestb5e19ee240ab
sprintf-js@1.1.3
no fix listed
4
joplin/server:3.7.2:latest3f7b852959aa
sprintf-js@1.1.3
no fix listed
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
sprintf-js@1.0.3
no fix listed
3
pantsel/konga:latestc8172b75607d
sprintf-js@1.0.3
no fix listed
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
sprintf-js@1.0.3
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
sprintf-js@1.0.3
no fix listed
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sprintf-js@1.0.3
no fix listed
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
sprintf-js@1.0.3
no fix listed
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
sprintf-js@1.0.3
no fix listed
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
sprintf-js@1.0.3
no fix listed
2
epamedp/krci-portal:0.8.0687acf641097
sprintf-js@1.1.3
no fix listed
2
etherpad/etherpad:3.3.6:latest98d395769b3b
sprintf-js@1.0.3
no fix listed
2
ethersphere/bee-localchain:latest0558799ca992
sprintf-js@1.0.3
no fix listed
2
freikin/dawarich:1.15.2e58334ca5697
sprintf-js@1.1.2
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
sprintf-js@1.0.3
no fix listed
2
governify/assets-manager:v1.4.12987672448c7
sprintf-js@1.0.3
no fix listed
2
governify/director:v1.4.0608c6940bb98
sprintf-js@1.0.3
no fix listed
2
governify/registry:v3.4.0d3f37f4f8168
sprintf-js@1.0.3
no fix listed
2
governify/render:v2.2.0daeca1ce28e6
sprintf-js@1.0.3
no fix listed
2
governify/reporter:v2.2.038595913458f
sprintf-js@1.0.3
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
sprintf-js@1.0.3
no fix listed
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sprintf-js@1.1.3
no fix listed
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
sprintf-js@1.0.3
no fix listed
2
library/arangodb:3.11.81e75d74954a4
sprintf-js@1.0.3
no fix listed
2
library/mongo-express:1.0.2:latest1b23d7976f02
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.5.4917318f9d7be
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:1.23.1396510915e6be
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.3.29aeb4e51d038
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
sprintf-js@1.1.3
no fix listed
2
louislam/uptime-kuma:2.5.5c74379ac4509
sprintf-js@1.1.3
no fix listed
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
sprintf-js@1.0.3
no fix listed
2
mesosphere/kommander:6.100.13917e82333a9
sprintf-js@1.0.3
no fix listed
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
sprintf-js@1.0.3
no fix listed
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
sprintf-js@1.0.3
no fix listed
2
mojaloop/reporting:v12.1.0d480a62103d6
sprintf-js@1.1.3
no fix listed
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sprintf-js@1.1.3
no fix listed
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sprintf-js@1.0.3
no fix listed
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
sprintf-js@1.1.3
no fix listed
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sprintf-js@1.0.3
no fix listed
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
sprintf-js@1.0.3
no fix listed
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
sprintf-js@1.0.3
no fix listed
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
sprintf-js@1.0.3
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
sprintf-js@1.0.3
no fix listed
2
n8nio/n8n:2.36.714c4285bc303
sprintf-js@1.0.3
no fix listed
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
sprintf-js@1.0.3
no fix listed
2
outlinewiki/outline:0.69.1d060dcd8f9aa
sprintf-js@1.0.3
no fix listed
2
rajnandan1/kener:3.2.1930407afca731
sprintf-js@1.1.3
no fix listed
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
sprintf-js@1.1.3
no fix listed
2

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.