StackRadar

CVE-2026-101910

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
182
of 17,939 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 182 of 17,939 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.2.0, 10.3.1, 10.4.0, 10.5.010.5.1160
OSV records
GHSA-2vr4-cq9g-pvrc

Charts affected

182 by stars
ChartLatestAffected imagesRadar Score
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.2.0
10.5.1

Open the chart page →

22,454
fluxer-helmfluxer-helm0.3.01 of 18See more

fluxer-helm fluxer-helm 0.3.0

1 of the 18 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.5.1

Open the chart page →

29,230
garge-appgargeVerified publisher0.1.531 of 1See more

garge-app garge 0.1.53

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.5.1

Open the chart page →

646
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.5.1

Open the chart page →

1,223
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.2.0
10.5.1

Open the chart page →

6,984
affinehelmforgeVerified publisher1.0.11 of 3See more

affine helmforge 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.4.0
10.5.1

Open the chart page →

4,030
archiveboxhelmforgeVerified publisher1.1.131 of 1See more

archivebox helmforge 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.2.0
10.5.1

Open the chart page →

5,365
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.5.1

Open the chart page →

5,766
homarrhelmforgeVerified publisher1.2.111 of 1See more

homarr helmforge 1.2.11

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.5.1

Open the chart page →

482
hoppscotchhelmforgeVerified publisher1.1.121 of 2See more

hoppscotch helmforge 1.1.12

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.5.1

Open the chart page →

1,736
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
ip-address@10.3.1
10.5.1

Open the chart page →

95
matterbridgehelmforgeVerified publisher1.0.51 of 1See more

matterbridge helmforge 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.11e278cf685f91
ip-address@10.2.0
10.5.1

Open the chart page →

742
memoshelmforgeVerified publisher2.0.21 of 2See more

memos helmforge 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.239ec4a2e28987
ip-address@10.2.0
10.5.1

Open the chart page →

141
opencuthelmforgeVerified publisher1.1.101 of 5See more

opencut helmforge 1.1.10

1 of the 5 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.5.1

Open the chart page →

3,090
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.5.1

Open the chart page →

2,795
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.239ec4a2e28987
ip-address@10.2.0
10.5.1

Open the chart page →

365
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:24.21.0-alpineebfe2f904627
ip-address@10.2.0
10.5.1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.5.1

Open the chart page →

2,760
twentyhelmforgeVerified publisher1.0.32 of 5See more

twenty helmforge 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:24.21.0-alpineebfe2f904627
ip-address@10.2.0
10.5.1
twentycrm/twenty:v2.43.0b2b662b1bef1
ip-address@10.4.0
10.5.1

Open the chart page →

2,113
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
ip-address@10.5.0
10.5.1

Open the chart page →

2,182
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.405e164855fa1
ip-address@10.2.0
10.5.1

Open the chart page →

9,355
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.2.0
10.5.1

Open the chart page →

3,710
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.5.1

Open the chart page →

482
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.5.1

Open the chart page →

39,672
api-key-managerjtektVerified publisher0.3.01 of 4See more

api-key-manager jtekt 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/api-key-manager-api:v0.1.175a48d987e0f
ip-address@10.2.0
10.5.1

Open the chart page →

6,338
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.2.0
10.5.1

Open the chart page →

3,357
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/node:lts-alpineebfe2f904627
ip-address@10.2.0
10.5.1

Open the chart page →

2,414
cdashkitwareVerified publisher0.20.01 of 3See more

cdash kitware 0.20.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
kitware/cdash:v5.4.0da5abe941506
ip-address@10.2.0
10.5.1

Open the chart page →

11,960
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.5.1

Open the chart page →

2,922
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.5.1

Open the chart page →

39,672
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.5.1

Open the chart page →

35,383
libredb-studiolibredb-studio-oci0.1.721 of 1See more

libredb-studio libredb-studio-oci 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
ip-address@10.5.0
10.5.1

Open the chart page →

989
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.2.0
10.5.1

Open the chart page →

1,909
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.5.1

Open the chart page →

35,383
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@10.2.0
10.5.1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@10.2.0
10.5.1

Open the chart page →

3,008
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.5.1

Open the chart page →

8,923
mcp-kubernetesmcp-helmVerified publisher0.2.71 of 1See more

mcp-kubernetes mcp-helm 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
mcp/kubernetes:latest5ffbf7f0a8aa
ip-address@10.2.0
10.5.1

Open the chart page →

6,010
homarrmedia-servarrVerified publisher0.55.31 of 1See more

homarr media-servarr 0.55.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.5.1

Open the chart page →

482
miot-dashboard-servermicroboxlabs0.1.21 of 1See more

miot-dashboard-server microboxlabs 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-dashboard-server:latest690057f3a1ee
ip-address@10.2.0
10.5.1

Open the chart page →

118
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
ip-address@10.5.0
10.5.1

Open the chart page →

10,913
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
ip-address@10.5.0
10.5.1

Open the chart page →

10,913
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.5.1

Open the chart page →

1,934
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.5.1

Open the chart page →

1,237
ixyneoskop2.2.01 of 1See more

ixy neoskop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
neoskop/ixy:2.2.015a480e34778
ip-address@10.2.0
10.5.1

Open the chart page →

311
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:mainc134ac2fa289
ip-address@10.2.0
10.5.1

Open the chart page →

505
cloakbrowser-mcpobeoneVerified publisher0.3.31 of 1See more

cloakbrowser-mcp obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
ip-address@10.5.0
10.5.1

Open the chart page →

2,475
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.5.1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.5.1

Open the chart page →

5,690
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.5.1

Open the chart page →

1,237
portalplatform-mesh-portal0.21.11 of 1See more

portal platform-mesh-portal 0.21.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.27.16a7ecd5a0dc2
ip-address@10.4.0
10.5.1

Open the chart page →

118
prismeai-coreprismeai1.12.34 of 7See more

prismeai-core prismeai 1.12.3

4 of the 7 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
ip-address@10.5.0
10.5.1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
ip-address@10.5.0
10.5.1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
ip-address@10.5.0
10.5.1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
ip-address@10.5.0
10.5.1

Open the chart page →

3,952
code-serverquench-code-serverVerified publisher0.0.121 of 1See more

code-server quench-code-server 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/code-serverdigest-pinned1e81c19f0149
ip-address@10.3.1
10.5.1

Open the chart page →

57

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/api-key-manager-api:v0.1.175a48d987e0f
ip-address@10.2.0
10.5.1
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.5.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
ip-address@10.4.0
10.5.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
ip-address@10.4.0
10.5.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.94.09d9860c05c39
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.