StackRadar

CVE-2026-101910

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
182
of 17,939 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 182 of 17,939 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.2.0, 10.3.1, 10.4.0, 10.5.010.5.1160
OSV records
GHSA-2vr4-cq9g-pvrc

Charts affected

182 by stars
ChartLatestAffected imagesRadar Score
homepagequench-homepageVerified publisher0.0.21 of 1See more

homepage quench-homepage 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/homepagedigest-pinned5af95ab01e8e
ip-address@10.5.0
10.5.1

Open the chart page →

63
unleashquench-unleashVerified publisher0.0.51 of 2See more

unleash quench-unleash 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/unleashdigest-pinned85b22c79b8cf
ip-address@10.3.1
10.5.1

Open the chart page →

130
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
ip-address@10.4.0
10.5.1

Open the chart page →

1,775
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.5.1

Open the chart page →

335
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.2.0
10.5.1

Open the chart page →

6,984
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.5.1

Open the chart page →

32,155
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
ip-address@10.5.0
10.5.1

Open the chart page →

3,324
rybbitrybbit-helm1.3.22 of 7See more

rybbit rybbit-helm 1.3.2

2 of the 7 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.5.1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.5.1

Open the chart page →

6,544
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.5.1

Open the chart page →

453
joplin-serverschoenwald1.0.31 of 1See more

joplin-server schoenwald 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
joplin/server:3.7.23f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

2,721
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.5.0
10.5.1

Open the chart page →

31,952
seerr-chartseerr-chartVerified publisher3.10.01 of 1See more

seerr-chart seerr-chart 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.5.027602401178d
ip-address@10.2.0
10.5.1

Open the chart page →

1,933
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1

Open the chart page →

2,895
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1

Open the chart page →

6,186
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1

Open the chart page →

999
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
supabase/storage-api:latest5fea789899d4
ip-address@10.2.0
10.5.1

Open the chart page →

9,174
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

5,991
altinnendata-apptumogroup0.1.221 of 1See more

altinnendata-app tumogroup 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.68bc03653f87e
ip-address@10.5.0
10.5.1

Open the chart page →

646
nstuning-apptumogroup0.1.221 of 1See more

nstuning-app tumogroup 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.15b7cc8f543551
ip-address@10.5.0
10.5.1

Open the chart page →

646
pyttogpanne-apptumogroup0.1.41 of 1See more

pyttogpanne-app tumogroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/pyttogpanne-app:v1.0.3706b0218f7b4
ip-address@10.5.0
10.5.1

Open the chart page →

646
sjolystinnovation-apptumogroup0.1.51 of 1See more

sjolystinnovation-app tumogroup 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/sjolystinnovation-app:v1.3.04ce832347953
ip-address@10.5.0
10.5.1

Open the chart page →

646
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.5.1

Open the chart page →

5,790
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
ip-address@10.5.0
10.5.1

Open the chart page →

936
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
ip-address@10.5.0
10.5.1

Open the chart page →

404
fossflowunxwaresVerified publisher2026.2.11 of 1See more

fossflow unxwares 2026.2.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
stnsmith/fossflow:lateste448ab346cb3
ip-address@10.5.0
10.5.1

Open the chart page →

191
devportalveecode-platform-nextVerified publisher0.1.251 of 1See more

devportal veecode-platform-next 0.1.25

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned7a3d61de5e5e
ip-address@10.2.0
10.5.1

Open the chart page →

2,015
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.5.1

Open the chart page →

74,473
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.5.1

Open the chart page →

1,957
opensearch-dashboardswener3.8.01 of 1See more

opensearch-dashboards wener 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@10.2.0
10.5.1

Open the chart page →

4,020
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
trackerforce/switcher-resolver-node:latest67e2c261f7b4
ip-address@10.2.0
10.5.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.5.0
10.5.1
1
twentycrm/twenty:latest:v2.41.047bcefe4e497
ip-address@10.4.0
10.5.1
1
twentycrm/twenty:v2.43.0b2b662b1bef1
ip-address@10.4.0
10.5.1
1
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.5.1
1
veecode/devportal7a3d61de5e5e
ip-address@10.2.0
10.5.1
1
wsjbr/duplistatus:1.5.0bede86cf183f
ip-address@10.2.0
10.5.1
1
xxczaki/discord-bot:3bf18776db30d6f5e1d8fc9ece62f13c913548aa695cbc36b5fa
ip-address@10.2.0
10.5.1
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@10.5.0
10.5.1
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.5.1
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.5.1
1
ghcr.io/automation64/toolbox/oraclelinux-9-toolbox:latest7af2216c7b9e
ip-address@10.2.0
10.5.1
1
ghcr.io/backstage/backstage:lateste2a48bb6ab55
ip-address@10.2.0
10.5.1
1
ghcr.io/bluesky-social/pds:0.405e164855fa1
ip-address@10.2.0
10.5.1
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
ip-address@10.5.0
10.5.1
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.5.1
1
ghcr.io/cameri/nostream:mainc134ac2fa289
ip-address@10.2.0
10.5.1
1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.5.1
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.5.1
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.5.1
1
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.5.1
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.5.1
1
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.2.0
10.5.1
1
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.5.1
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.5.1
1
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
ip-address@10.5.0
10.5.1
1
ghcr.io/immich-app/immich-server:v3.2.279cc1623323d
ip-address@10.2.0
10.5.1
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ip-address@10.2.0
10.5.1
1
ghcr.io/lockdep/stackradar-scanner:0.4.073cbeb990cf4
ip-address@10.5.0
10.5.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@10.2.0
10.5.1
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@10.2.0
10.5.1
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.5.1
1
ghcr.io/mend/renovate-ee-server:15.6.087b77989f48d
ip-address@10.2.0
10.5.1
1
ghcr.io/microboxlabs/miot-dashboard-server:latest690057f3a1ee
ip-address@10.2.0
10.5.1
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
ip-address@10.2.0
10.5.1
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.5.1
1
ghcr.io/platform-mesh/portal:v0.27.16a7ecd5a0dc2
ip-address@10.4.0
10.5.1
1
ghcr.io/quenchworks/images/code-server1e81c19f0149
ip-address@10.3.1
10.5.1
1
ghcr.io/quenchworks/images/homepage5af95ab01e8e
ip-address@10.5.0
10.5.1
1
ghcr.io/quenchworks/images/unleash85b22c79b8cf
ip-address@10.3.1
10.5.1
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
ip-address@10.5.0
10.5.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.5.1
1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.5.1
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.5.1
1
ghcr.io/seerr-team/seerr:v3.5.027602401178d
ip-address@10.2.0
10.5.1
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.5.1
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.9.162614fd45986
ip-address@10.2.0
10.5.1
1
ghcr.io/thotischner/observability-mcp:3.9.11775e1e84d5d1
ip-address@10.3.1
10.5.1
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.4.0
10.5.1
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.