StackRadar

CVE-2026-101910

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
182
of 17,939 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 182 of 17,939 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.2.0, 10.3.1, 10.4.0, 10.5.010.5.1160
OSV records
GHSA-2vr4-cq9g-pvrc

Charts affected

182 by stars
ChartLatestAffected imagesRadar Score
n8ncommunity-chartsVerified publisher1.24.421 of 1See more

n8n community-charts 1.24.42

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
n8nio/n8n:2.40.59f693fd55655
ip-address@10.3.1
10.5.1

Open the chart page →

865
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.3.1
10.5.1

Open the chart page →

1,237
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.5.1

Open the chart page →

32,092
backstagebackstageOfficialVerified publisher2.10.21 of 1See more

backstage backstage 2.10.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:lateste2a48bb6ab55
ip-address@10.2.0
10.5.1

Open the chart page →

1,038
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.5.1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.2.0
10.5.1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.2.0
10.5.1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.2.0
10.5.1

Open the chart page →

12,735
opensearch-dashboardsopensearch-project-helm-chartsVerified publisher3.8.01 of 1See more

opensearch-dashboards opensearch-project-helm-charts 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
penpotpenpotOfficialVerified publisher1.10.02 of 5See more

penpot penpot 1.10.0

2 of the 5 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
penpotapp/exporter:2.18.0beb2c2bd9660
ip-address@10.3.1
10.5.1
penpotapp/mcp:2.18.09270da9fab95
ip-address@10.5.0
10.5.1

Open the chart page →

5,276
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.5.1

Open the chart page →

1,240
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip-address@10.2.0
10.5.1

Open the chart page →

7,546
chatwootchatwootVerified publisher2.0.251 of 3See more

chatwoot chatwoot 2.0.25

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.16.2f9b071ffe678
ip-address@10.2.0
10.5.1

Open the chart page →

9,001
homarrhomarr-labsOfficialVerified publisher8.29.21 of 1See more

homarr homarr-labs 8.29.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.5.1

Open the chart page →

482
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
ip-address@10.5.0
10.5.1

Open the chart page →

2,284
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
ip-address@10.2.0
10.5.1

Open the chart page →

6,076
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
ip-address@10.2.0
10.5.1

Open the chart page →

3,161
velero-uiotwldVerified publisher0.16.01 of 1See more

velero-ui otwld 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.31c228d9ef71b
ip-address@10.2.0
10.5.1

Open the chart page →

1,500
budibasebudibase0.0.0-master2 of 7See more

budibase budibase 0.0.0-master

2 of the 7 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.5.1
budibase/worker:3.41.3de5e2e560ce8
ip-address@10.3.1
10.5.1

Open the chart page →

10,680
openclawopenclawVerified publisher1.94.02 of 2See more

openclaw openclaw 1.94.0

2 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
ip-address@10.5.0
10.5.1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.94.09d9860c05c39
ip-address@10.2.0
10.5.1

Open the chart page →

3,445
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1

Open the chart page →

3,199
n8nhelmforgeVerified publisher2.1.21 of 2See more

n8n helmforge 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.3fdce8f852ac7
ip-address@10.3.1
10.5.1

Open the chart page →

952
homepagem0nsterrr-homepageVerified publisher5.4.01 of 1See more

homepage m0nsterrr-homepage 5.4.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.4.0643bd0be730d
ip-address@10.5.0
10.5.1

Open the chart page →

395
docmosthelmforgeVerified publisher1.4.01 of 4See more

docmost helmforge 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
ip-address@10.3.1
10.5.1

Open the chart page →

3,567
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
ip-address@10.4.0
10.5.1

Open the chart page →

1,006
kuttchristianhuthVerified publisher9.11.21 of 3See more

kutt christianhuth 9.11.2

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
kutt/kutt:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.5.1

Open the chart page →

538
dialdialOfficialVerified publisher8.0.01 of 4See more

dial dial 8.0.0

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
epam/ai-dial-chat:1.1.0974c1ddceab6
ip-address@10.5.0
10.5.1

Open the chart page →

2,062
heimdallheimdallOfficialVerified publisher3.3.31 of 2See more

heimdall heimdall 3.3.3

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
mitre/heimdall2:release-latest06f6e72d416a
ip-address@10.4.0
10.5.1

Open the chart page →

2,021
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.5.1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ip-address@10.2.0
10.5.1

Open the chart page →

10,478
libredb-studiolibredb-studioVerified publisher0.1.721 of 1See more

libredb-studio libredb-studio 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
ip-address@10.5.0
10.5.1

Open the chart page →

989
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
ip-address@10.2.0
10.5.1

Open the chart page →

775
duplistatusduplistatusVerified publisher1.3.01 of 2See more

duplistatus duplistatus 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.5.0bede86cf183f
ip-address@10.2.0
10.5.1

Open the chart page →

887
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
diygod/rsshub:latest22845ada2f14
ip-address@10.2.0
10.5.1

Open the chart page →

1,493
hermes-agenthermes-agentVerified publisher1.16.01 of 1See more

hermes-agent hermes-agent 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.5.1

Open the chart page →

5,766
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
shieldsio/shields:nextf0fccbce3b75
ip-address@10.2.0
10.5.1

Open the chart page →

1,586
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1

Open the chart page →

1,077
wgerwgerOfficialVerified publisher2.0.01 of 7See more

wger wger 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latest413a0c813e96
ip-address@10.2.0
10.5.1

Open the chart page →

7,565
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.5.1

Open the chart page →

1,161
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.5.1

Open the chart page →

6,488
kinesisaws-kinesis-local0.8.01 of 1See more

kinesis aws-kinesis-local 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.5.1

Open the chart page →

411
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.5.1

Open the chart page →

2,143
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.5.1

Open the chart page →

2,578
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.5.1

Open the chart page →

156
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.5.1

Open the chart page →

1,988
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.5.1

Open the chart page →

39,657
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.5.1

Open the chart page →

9,782
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.5.1

Open the chart page →

8,071
jellystatdjjudas21Verified publisher1.0.11 of 1See more

jellystat djjudas21 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.12e61c759ec706
ip-address@10.2.0
10.5.1

Open the chart page →

1,756
joplin-serverdjjudas21Verified publisher6.0.01 of 1See more

joplin-server djjudas21 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
joplin/server:3.7.23f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

2,721
domain-lockerdomain-locker0.3.11 of 2See more

domain-locker domain-locker 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
lissy93/domain-locker:latest58a903b2cdd9
ip-address@10.2.0
10.5.1

Open the chart page →

700
growthbookgrowthbook5.1.01 of 2See more

growthbook growthbook 5.1.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
growthbook/growthbook:5.1.0c8a124f55dca
ip-address@10.5.0
10.5.1

Open the chart page →

447
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.5.1

Open the chart page →

1,517
langflow-idelangflow0.1.21 of 2See more

langflow-ide langflow 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
langflowai/langflow:latest79c02794adeb
ip-address@10.3.1
10.5.1

Open the chart page →

4,270

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/api-key-manager-api:v0.1.175a48d987e0f
ip-address@10.2.0
10.5.1
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.5.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
ip-address@10.4.0
10.5.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
ip-address@10.4.0
10.5.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.94.09d9860c05c39
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.