StackRadar

CVE-2026-101910

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
182
of 17,939 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 1
affected package

ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 182 of 17,939 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.2.0, 10.3.1, 10.4.0, 10.5.010.5.1160
OSV records
GHSA-2vr4-cq9g-pvrc

Charts affected

182 by stars
ChartLatestAffected imagesRadar Score
homepagequench-homepageVerified publisher0.0.21 of 1See more

homepage quench-homepage 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/homepagedigest-pinned5af95ab01e8e
ip-address@10.5.0
10.5.1

Open the chart page →

63
unleashquench-unleashVerified publisher0.0.51 of 2See more

unleash quench-unleash 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/unleashdigest-pinned85b22c79b8cf
ip-address@10.3.1
10.5.1

Open the chart page →

130
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
ip-address@10.4.0
10.5.1

Open the chart page →

1,775
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.5.1

Open the chart page →

335
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.2.0
10.5.1

Open the chart page →

6,984
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.5.1

Open the chart page →

32,155
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
ip-address@10.5.0
10.5.1

Open the chart page →

3,324
rybbitrybbit-helm1.3.22 of 7See more

rybbit rybbit-helm 1.3.2

2 of the 7 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.5.1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.5.1

Open the chart page →

6,544
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.5.1

Open the chart page →

453
joplin-serverschoenwald1.0.31 of 1See more

joplin-server schoenwald 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
joplin/server:3.7.23f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

2,721
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.5.0
10.5.1

Open the chart page →

31,952
seerr-chartseerr-chartVerified publisher3.10.01 of 1See more

seerr-chart seerr-chart 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.5.027602401178d
ip-address@10.2.0
10.5.1

Open the chart page →

1,933
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1

Open the chart page →

2,895
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1

Open the chart page →

6,186
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1

Open the chart page →

999
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
supabase/storage-api:latest5fea789899d4
ip-address@10.2.0
10.5.1

Open the chart page →

9,174
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

5,991
altinnendata-apptumogroup0.1.221 of 1See more

altinnendata-app tumogroup 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.68bc03653f87e
ip-address@10.5.0
10.5.1

Open the chart page →

646
nstuning-apptumogroup0.1.221 of 1See more

nstuning-app tumogroup 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.15b7cc8f543551
ip-address@10.5.0
10.5.1

Open the chart page →

646
pyttogpanne-apptumogroup0.1.41 of 1See more

pyttogpanne-app tumogroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/pyttogpanne-app:v1.0.3706b0218f7b4
ip-address@10.5.0
10.5.1

Open the chart page →

646
sjolystinnovation-apptumogroup0.1.51 of 1See more

sjolystinnovation-app tumogroup 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
sondresjo/sjolystinnovation-app:v1.3.04ce832347953
ip-address@10.5.0
10.5.1

Open the chart page →

646
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.5.1

Open the chart page →

5,790
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
ip-address@10.5.0
10.5.1

Open the chart page →

936
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
ip-address@10.5.0
10.5.1

Open the chart page →

404
fossflowunxwaresVerified publisher2026.2.11 of 1See more

fossflow unxwares 2026.2.1

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
stnsmith/fossflow:lateste448ab346cb3
ip-address@10.5.0
10.5.1

Open the chart page →

191
devportalveecode-platform-nextVerified publisher0.1.251 of 1See more

devportal veecode-platform-next 0.1.25

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned7a3d61de5e5e
ip-address@10.2.0
10.5.1

Open the chart page →

2,015
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.5.1

Open the chart page →

74,473
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.5.1

Open the chart page →

1,957
opensearch-dashboardswener3.8.01 of 1See more

opensearch-dashboards wener 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@10.2.0
10.5.1

Open the chart page →

4,020
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101910.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1
4
joplin/server:3.7.2:latest3f7b852959aa
ip-address@10.2.0
10.5.1
3
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1
3
library/node:24.21.0-alpine:lts-alpineebfe2f904627
ip-address@10.2.0
10.5.1
3
localstack/localstack:latest4abc29e923e5
ip-address@10.5.0
10.5.1
3
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1
3
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.5.1
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1
3
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.5.1
2
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.5.1
2
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.5.1
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.5.1
2
langflowai/langflow:latest79c02794adeb
ip-address@10.3.1
10.5.1
2
library/node:24.21.0-alpine3.239ec4a2e28987
ip-address@10.2.0
10.5.1
2
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.5.0
10.5.1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.5.1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.5.1
2
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.5.1
2
nodered/node-red:5.0.7:latesta649dd711d55
ip-address@10.2.0
10.5.1
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.5.1
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.5.1
2
requarks/wiki:2:latest68f0d1848261
ip-address@10.2.0
10.5.1
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
ip-address@10.5.0
10.5.1
2
ghcr.io/gethomepage/homepage:latest:v2.4.0643bd0be730d
ip-address@10.5.0
10.5.1
2
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
ip-address@10.5.0
10.5.1
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.2.0
10.5.1
2
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
ip-address@10.2.0
10.5.1
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
ip-address@10.2.0
10.5.1
2
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.2.0
10.5.1
1
bluerange/bluerange-mosquitto:2690a4e5b92cc6
ip-address@10.4.0
10.5.1
1
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.5.1
1
budibase/worker:3.41.3de5e2e560ce8
ip-address@10.3.1
10.5.1
1
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.5.1
1
chatwoot/chatwoot:v4.16.2f9b071ffe678
ip-address@10.2.0
10.5.1
1
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.5.1
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.5.1
1
cyfershepard/jellystat:1.1.12e61c759ec706
ip-address@10.2.0
10.5.1
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip-address@10.2.0
10.5.1
1
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.5.1
1
diygod/rsshub:latest22845ada2f14
ip-address@10.2.0
10.5.1
1
docmost/docmost:0.96.0b56947fcfd08
ip-address@10.3.1
10.5.1
1
ducktors/turborepo-remote-cache:latest8aa1c158d885
ip-address@10.2.0
10.5.1
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.5.1
1
epam/ai-dial-admin-frontend:0.21.01ecee9f1aa09
ip-address@10.4.0
10.5.1
1
epam/ai-dial-chat:1.1.0974c1ddceab6
ip-address@10.5.0
10.5.1
1
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.5.1
1
evershop/evershop:latestd0823576f91b
ip-address@10.5.0
10.5.1
1
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.5.1
1
fosrl/pangolin:latest00cfb631097a
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.