StackRadar

CVE-2026-101911

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-h3mg-xc3c-68pw
Trending
Rank 30 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.1.0
10.7.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.1.0
10.7.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.1.0
10.7.1
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ip-address@9.0.5
10.7.1
1
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.7.1
1
sharanalwar/redchef-frontend:latest5e82950b16b7
ip-address@9.0.5
10.7.1
1
shieldsio/shields:nextf0fccbce3b75
ip-address@10.2.0
10.7.1
1
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.7.1
1
shyamkrishna21/shopsync:latest3998b83def53
ip-address@9.0.5
10.7.1
1
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
ip-address@9.0.5
10.7.1
1
skylenet/ethstats-server:pow-latestd757cc016198
ip-address@5.9.4
10.7.1
1
sondresjo/altinnendata-app:v1.9.73150a3038fbf
ip-address@10.5.0
10.7.1
1
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.7.1
1
sondresjo/nstuning-app:v1.6.15b7cc8f543551
ip-address@10.5.0
10.7.1
1
sondresjo/pyttogpanne-app:v1.0.3706b0218f7b4
ip-address@10.5.0
10.7.1
1
sondresjo/sjolystinnovation-app:v1.3.04ce832347953
ip-address@10.5.0
10.7.1
1
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.26.3092384dba45d
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
ip-address@9.0.5
10.7.1
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.26.379f14a2bf931
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
ip-address@9.0.5
10.7.1
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
ip-address@9.0.5
10.7.1
1
stnsmith/fossflow:lateste448ab346cb3
ip-address@10.5.0
10.7.1
1
supabase/postgres-meta:v0.96.6a84cc713585e
ip-address@9.0.5
10.7.1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
ip-address@9.0.5
10.7.1
1
supabase/storage-api:latest5fea789899d4
ip-address@10.2.0
10.7.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.1.0
10.7.1
1
supabase/storage-api:v1.12.0f983fb50bd95
ip-address@9.0.5
10.7.1
1
supabase/studio:20241021-9f9b08326d8070c55e9
ip-address@9.0.5
10.7.1
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
ip-address@10.1.0
10.7.1
1
supabase/studio:latestfdb56cfa1705
ip-address@10.1.0
10.7.1
1
supporttools/uptime-kuma:v2.6f8a49ed65809
ip-address@9.0.5
10.7.1
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
ip-address@10.5.0
10.7.1
1
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.7.1
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.7.1
1
tensorzero/ui:2026.6.0f2563d54724e
ip-address@10.0.1
10.7.1
1
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.