StackRadar

CVE-2026-101910

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
182
of 17,939 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 182 of 17,939 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.2.0, 10.3.1, 10.4.0, 10.5.010.5.1160
OSV records
GHSA-2vr4-cq9g-pvrc

Charts affected

182 by stars
ChartLatestAffected imagesRadar Score
langflow-runtimelangflow0.1.11 of 1See more

langflow-runtime langflow 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
langflowai/langflow:latest79c02794adeb
ip-address@10.3.1
10.5.1

Open the chart page →

159
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.5.1

Open the chart page →

1,240
mend-renovate-enterprise-editionmend-renovateVerified publisher10.6.01 of 2See more

mend-renovate-enterprise-edition mend-renovate 10.6.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/mend/renovate-ee-server:15.6.087b77989f48d
ip-address@10.2.0
10.5.1

Open the chart page →

38,104
observability-mcpobservability-mcpOfficialVerified publisher2.9.121 of 2See more

observability-mcp observability-mcp 2.9.12

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/thotischner/observability-mcp:3.9.11775e1e84d5d1
ip-address@10.3.1
10.5.1

Open the chart page →

37
growthbookone-acre-fundVerified publisher0.3.01 of 3See more

growthbook one-acre-fund 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
growthbook/growthbook:latestcbf1bc59e9a9
ip-address@10.5.0
10.5.1

Open the chart page →

1,249
kuttone-acre-fundVerified publisher0.2.51 of 1See more

kutt one-acre-fund 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
kutt/kutt:latestfa3d24a89b04
ip-address@10.2.0
10.5.1

Open the chart page →

525
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.5.1

Open the chart page →

7,722
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.5.0
10.5.1

Open the chart page →

33,426
immichsecustorVerified publisher2.0.61 of 1See more

immich secustor 2.0.6

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.279cc1623323d
ip-address@10.2.0
10.5.1

Open the chart page →

3,427
helm64-toolboxserdigital64Verified publisher0.4.01 of 1See more

helm64-toolbox serdigital64 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/automation64/toolbox/oraclelinux-9-toolbox:latest7af2216c7b9e
ip-address@10.2.0
10.5.1

Open the chart page →

1,551
wg-easyslybase-wg-easyVerified publisher1.2.01 of 1See more

wg-easy slybase-wg-easy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:15.4.00e7bc9d34e86
ip-address@10.2.0
10.5.1

Open the chart page →

775
stackradar-scannerstackradarVerified publisher0.4.01 of 1See more

stackradar-scanner stackradar 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/lockdep/stackradar-scanner:0.4.073cbeb990cf4
ip-address@10.5.0
10.5.1

Open the chart page →

1,271
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.2.0
10.5.1

Open the chart page →

19,207
switcher-apiswitcherapiOfficialVerified publisher1.3.52 of 3See more

switcher-api switcherapi 1.3.5

2 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
trackerforce/switcher-api:latest28ee0c4e0b88
ip-address@10.2.0
10.5.1
trackerforce/switcher-resolver-node:latest67e2c261f7b4
ip-address@10.2.0
10.5.1

Open the chart page →

722
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.5.1

Open the chart page →

2,667
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@10.2.0
10.5.1

Open the chart page →

4,020
discord-botxxczakiVerified publisher0.32.51 of 2See more

discord-bot xxczaki 0.32.5

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
xxczaki/discord-bot:3bf18776db30d6f5e1d8fc9ece62f13c913548aa695cbc36b5fa
ip-address@10.2.0
10.5.1

Open the chart page →

543
crowdsec-web-uizekker6Verified publisher0.52.01 of 1See more

crowdsec-web-ui zekker6 0.52.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.9.162614fd45986
ip-address@10.2.0
10.5.1

Open the chart page →

1,158
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.5.1

Open the chart page →

1,409
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.5.1

Open the chart page →

1,432
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.5.0
10.5.1

Open the chart page →

31,952
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest8aa1c158d885
ip-address@10.2.0
10.5.1

Open the chart page →

587
homepagealareira1.0.11 of 1See more

homepage alareira 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:latest643bd0be730d
ip-address@10.5.0
10.5.1

Open the chart page →

395
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
ip-address@10.5.0
10.5.1

Open the chart page →

2,338
excalidashalekcVerified publisher1.4.01 of 2See more

excalidash alekc 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@10.5.0
10.5.1

Open the chart page →

990
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
fosrl/pangolin:latest00cfb631097a
ip-address@10.2.0
10.5.1

Open the chart page →

1,981
bluerange-mosquittobluerangeOfficialVerified publisher1.1.01 of 1See more

bluerange-mosquitto bluerange 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:2690a4e5b92cc6
ip-address@10.4.0
10.5.1

Open the chart page →

137
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1

Open the chart page →

79,572
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.5.1

Open the chart page →

477
opencloudcommunity-opencloud3.1.01 of 13See more

opencloud community-opencloud 3.1.0

1 of the 13 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.5.1

Open the chart page →

9,829
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.5.1

Open the chart page →

592
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

280
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

280
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

280
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.01 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

1,525
dial-admindialVerified publisher0.19.01 of 3See more

dial-admin dial 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.21.01ecee9f1aa09
ip-address@10.4.0
10.5.1

Open the chart page →

3,846
node-reddjdl-charts0.33.01 of 1See more

node-red djdl-charts 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nodered/node-red:latesta649dd711d55
ip-address@10.2.0
10.5.1

Open the chart page →

156
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.5.1

Open the chart page →

7,928
clickhouse-monitoringduyet0.1.31 of 2See more

clickhouse-monitoring duyet 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.5.1

Open the chart page →

1,093
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.5.1

Open the chart page →

744
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.5.1

Open the chart page →

1,105
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.5.1

Open the chart page →

32,092
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.5.1

Open the chart page →

2,184
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.5.1

Open the chart page →

888
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.5.1

Open the chart page →

2,927
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.5.1

Open the chart page →

2,670
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1

Open the chart page →

7,377
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1

Open the chart page →

7,377
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.5.1

Open the chart page →

6,195
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.5.0
10.5.1

Open the chart page →

2,066

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
growthbook/growthbook:5.1.0c8a124f55dca
ip-address@10.5.0
10.5.1
1
growthbook/growthbook:latestcbf1bc59e9a9
ip-address@10.5.0
10.5.1
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.5.1
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.5.1
1
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.5.1
1
journeyapps/powersync-service:latest413a0c813e96
ip-address@10.2.0
10.5.1
1
kitware/cdash:v5.4.0da5abe941506
ip-address@10.2.0
10.5.1
1
langflowai/langflow:1.12.334055a07d446
ip-address@10.3.1
10.5.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.5.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.5.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.2.0
10.5.1
1
library/ghost:6.41.129773d6be407
ip-address@10.2.0
10.5.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.5.1
1
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.5.1
1
lissy93/domain-locker:latest58a903b2cdd9
ip-address@10.2.0
10.5.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.5.1
1
luligu/matterbridge:3.10.11e278cf685f91
ip-address@10.2.0
10.5.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.5.1
1
mcp/kubernetes:latest5ffbf7f0a8aa
ip-address@10.2.0
10.5.1
1
mitre/heimdall2:release-latest06f6e72d416a
ip-address@10.4.0
10.5.1
1
n8nio/n8n:2.40.59f693fd55655
ip-address@10.3.1
10.5.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.3.1
10.5.1
1
n8nio/n8n:2.41.3fdce8f852ac7
ip-address@10.3.1
10.5.1
1
neoskop/ixy:2.2.015a480e34778
ip-address@10.2.0
10.5.1
1
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.5.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.2.0
10.5.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.5.1
1
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.5.1
1
otwld/velero-ui:0.10.31c228d9ef71b
ip-address@10.2.0
10.5.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.5.1
1
penpotapp/exporter:2.18.0beb2c2bd9660
ip-address@10.3.1
10.5.1
1
penpotapp/mcp:2.18.09270da9fab95
ip-address@10.5.0
10.5.1
1
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.5.1
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.2.0
10.5.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.2.0
10.5.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.2.0
10.5.1
1
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.5.1
1
shieldsio/shields:nextf0fccbce3b75
ip-address@10.2.0
10.5.1
1
sondresjo/altinnendata-app:v1.9.68bc03653f87e
ip-address@10.5.0
10.5.1
1
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.5.1
1
sondresjo/nstuning-app:v1.6.15b7cc8f543551
ip-address@10.5.0
10.5.1
1
sondresjo/pyttogpanne-app:v1.0.3706b0218f7b4
ip-address@10.5.0
10.5.1
1
sondresjo/sjolystinnovation-app:v1.3.04ce832347953
ip-address@10.5.0
10.5.1
1
stnsmith/fossflow:lateste448ab346cb3
ip-address@10.5.0
10.5.1
1
supabase/storage-api:latest5fea789899d4
ip-address@10.2.0
10.5.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.2.0
10.5.1
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
ip-address@10.5.0
10.5.1
1
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.5.1
1
trackerforce/switcher-api:latest28ee0c4e0b88
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.