CVE-2026-101910
MediumAdvisory
Published 28 Sept 2026In the index since 29 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 182
- of 17,939 indexed, latest versions
- Container images
- 160
- deployed by those charts
- Fix available
- 1 of 1
- affected package
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
Carried by container images the latest versions of 182 of 17,939 indexed charts deploy, on 160 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| ip-addressnpm | 10.2.0, 10.3.1, 10.4.0, 10.5.0 | 10.5.1 | 160 |
- OSV records
- GHSA-2vr4-cq9g-pvrc
Charts affected
182 by stars
Container images carrying it
160 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| decisionrules/ | 6a8f32aa11bc | ip-address | 10.5.1 | 4 |
| joplin/ | 3f7b852959aa | ip-address | 10.5.1 | 3 |
| library/ | 64af3819f927 | ip-address | 10.5.1 | 3 |
| library/ | ebfe2f904627 | ip-address | 10.5.1 | 3 |
| localstack/ | 4abc29e923e5 | ip-address | 10.5.1 | 3 |
| opensearchproject/ | 7fb7ec1b33f1 | ip-address | 10.5.1 | 3 |
| ghcr.io/ | f0fb462299af | ip-address | 10.5.1 | 3 |
| quay.io/ | 89bd85d7817f | ip-address | 10.5.1 | 3 |
| actualbudget/ | 552beab3dec8 | ip-address | 10.5.1 | 2 |
| epamedp/ | 687acf641097 | ip-address | 10.5.1 | 2 |
| homebridge/ | 77c685a40911 | ip-address | 10.5.1 | 2 |
| kutt/ | fa3d24a89b04 | ip-address | 10.5.1 | 2 |
| langflowai/ | 79c02794adeb | ip-address | 10.5.1 | 2 |
| library/ | 9ec4a2e28987 | ip-address | 10.5.1 | 2 |
| louislam/ | 917318f9d7be | ip-address | 10.5.1 | 2 |
| louislam/ | 9aeb4e51d038 | ip-address | 10.5.1 | 2 |
| louislam/ | a8610b3b4c38 | ip-address | 10.5.1 | 2 |
| n8nio/ | 14c4285bc303 | ip-address | 10.5.1 | 2 |
| nodered/ | a649dd711d55 | ip-address | 10.5.1 | 2 |
| nousresearch/ | fca358f12efd | ip-address | 10.5.1 | 2 |
| patrikx3/ | f19eb45b0694 | ip-address | 10.5.1 | 2 |
| requarks/ | 68f0d1848261 | ip-address | 10.5.1 | 2 |
| siscc/ | 12c5048f7402 | ip-address | 10.5.1 | 2 |
| ghcr.io/ | b1ba7b054af2 | ip-address | 10.5.1 | 2 |
| ghcr.io/ | 643bd0be730d | ip-address | 10.5.1 | 2 |
| ghcr.io/ | ce4d58724e25 | ip-address | 10.5.1 | 2 |
| ghcr.io/ | 7e2ef5261764 | ip-address | 10.5.1 | 2 |
| ghcr.io/ | f4768de5f616 | ip-address | 10.5.1 | 2 |
| ghcr.io/ | 0e7bc9d34e86 | ip-address | 10.5.1 | 2 |
| archivebox/ | 8c21bb233130 | ip-address | 10.5.1 | 1 |
| bluerange/ | 90a4e5b92cc6 | ip-address | 10.5.1 | 1 |
| budibase/ | 44fe6feab985 | ip-address | 10.5.1 | 1 |
| budibase/ | de5e2e560ce8 | ip-address | 10.5.1 | 1 |
| chainsafe/ | d717e4193699 | ip-address | 10.5.1 | 1 |
| chatwoot/ | f9b071ffe678 | ip-address | 10.5.1 | 1 |
| chocobozzz/ | 052712130691 | ip-address | 10.5.1 | 1 |
| continuoussecuritytooling/ | f04ecefab64e | ip-address | 10.5.1 | 1 |
| cyfershepard/ | e61c759ec706 | ip-address | 10.5.1 | 1 |
| dessalines/ | ee4c620d8e93 | ip-address | 10.5.1 | 1 |
| directus/ | 9c8470ea465c | ip-address | 10.5.1 | 1 |
| diygod/ | 22845ada2f14 | ip-address | 10.5.1 | 1 |
| docmost/ | b56947fcfd08 | ip-address | 10.5.1 | 1 |
| ducktors/ | 8aa1c158d885 | ip-address | 10.5.1 | 1 |
| eclipseaerios/ | a4b4c2e7fe62 | ip-address | 10.5.1 | 1 |
| epam/ | 1ecee9f1aa09 | ip-address | 10.5.1 | 1 |
| epam/ | 974c1ddceab6 | ip-address | 10.5.1 | 1 |
| ethpandaops/ | 1efa2fba6711 | ip-address | 10.5.1 | 1 |
| evershop/ | d0823576f91b | ip-address | 10.5.1 | 1 |
| foggbh/ | 8b7a2e5ecf4e | ip-address | 10.5.1 | 1 |
| fosrl/ | 00cfb631097a | ip-address | 10.5.1 | 1 |