StackRadar

CVE-2026-101911

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-h3mg-xc3c-68pw
Trending
Rank 30 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ip-address@9.0.5
10.7.1
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
ip-address@9.0.5
10.7.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
ip-address@9.0.5
10.7.1
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
ip-address@9.0.5
10.7.1
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
ip-address@9.0.5
10.7.1
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
ip-address@9.0.5
10.7.1
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ip-address@10.2.0
10.7.1
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
ip-address@9.0.5
10.7.1
1
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
ip-address@10.1.0
10.7.1
1
ghcr.io/krateoplatformops/deployment-service:1.2.59da9f93f2f731
ip-address@9.0.5
10.7.1
1
ghcr.io/krateoplatformops/terminal-client:0.1.36c7c965e739c
ip-address@9.0.5
10.7.1
1
ghcr.io/krateoplatformops/terminal-server:0.1.3f5fd8ba6fea3
ip-address@9.0.5
10.7.1
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
ip-address@9.0.5
10.7.1
1
ghcr.io/lerentis/bitwarden-crd-operator:0.18.0912b19a7f09a
ip-address@10.1.0
10.7.1
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
ip-address@10.1.0
10.7.1
1
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
ip-address@9.0.5
10.7.1
1
ghcr.io/linuxserver/pairdrop:version-v1.11.215b6792fcd48
ip-address@10.0.1
10.7.1
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
ip-address@5.9.4
10.7.1
1
ghcr.io/lockdep/stackradar-scanner:0.4.073cbeb990cf4
ip-address@10.1.0
10.7.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@9.0.5
10.7.1
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@9.0.5
10.7.1
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
ip-address@9.0.5
10.7.1
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
ip-address@9.0.5
10.7.1
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
ip-address@9.0.5
10.7.1
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
ip-address@9.0.5
10.7.1
1
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
ip-address@10.1.0
10.7.1
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.7.1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
ip-address@9.0.5
10.7.1
1
ghcr.io/mend/renovate-ee-server:15.6.087b77989f48d
ip-address@10.2.0
10.7.1
1
ghcr.io/michaelhaigh/pacman:latest0d6c5437d7fe
ip-address@10.1.0
10.7.1
1
ghcr.io/microboxlabs/miot-dashboard-server:latest690057f3a1ee
ip-address@10.2.0
10.7.1
1
ghcr.io/microboxlabs/miot-docs:latest84877c693d8a
ip-address@10.1.0
10.7.1
1
ghcr.io/microboxlabs/miot-docs:latesta44f3a5045b5
ip-address@10.1.0
10.7.1
1
ghcr.io/multica-ai/multica-web:v0.6.0b88402be269b
ip-address@10.1.0
10.7.1
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
ip-address@10.0.1
10.7.1
1
ghcr.io/openccu/openccu:3.89.11.202609193cfcb30e1921
ip-address@10.1.0
10.7.1
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
ip-address@10.2.0
10.7.1
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
ip-address@9.0.5
10.7.1
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
ip-address@9.0.5
10.7.1
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
ip-address@9.0.5
10.7.1
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
ip-address@9.0.5
10.7.1
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
ip-address@9.0.5
10.7.1
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
ip-address@9.0.5
10.7.1
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.7.1
1
ghcr.io/platform-mesh/portal:v0.27.16a7ecd5a0dc2
ip-address@10.4.0
10.7.1
1
ghcr.io/quenchworks/images/code-server114d65a2f0bb
ip-address@10.5.1
10.7.1
1
ghcr.io/quenchworks/images/homepage01bdc7364598
ip-address@10.5.1
10.7.1
1
ghcr.io/quenchworks/images/unleash3dde8e6ab802
ip-address@10.5.1
10.7.1
1
ghcr.io/quenchworks/images/uptime-kuma8037c42b1c70
ip-address@10.7.0
10.7.1
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
ip-address@9.0.5
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.