StackRadar

CVE-2026-101911

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-h3mg-xc3c-68pw
Trending
Rank 30 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101911.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
koenkk/zigbee2mqtt:2.14.1fef0de769dcd
ip-address@10.7.0
10.7.1
5
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.7.1
4
redis/redisinsight:3.8:latestb5e19ee240ab
ip-address@9.0.5
10.7.1
4
joplin/server:3.7.2:latest3f7b852959aa
ip-address@10.2.0
10.7.1
3
library/node:lts64af3819f927
ip-address@10.2.0
10.7.1
3
library/node:24.21.0-alpine:lts-alpineebfe2f904627
ip-address@10.2.0
10.7.1
3
localstack/localstack:latest4abc29e923e5
ip-address@10.5.0
10.7.1
3
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1
3
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1
3
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.7.1
3
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
ip-address@10.1.0
10.7.1
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ip-address@10.0.1
10.7.1
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.7.1
3
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.7.1
2
epamedp/krci-portal:0.8.0687acf641097
ip-address@9.0.5
10.7.1
2
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.7.1
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.7.1
2
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.7.1
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.7.1
2
langflowai/langflow:latest79c02794adeb
ip-address@10.3.1
10.7.1
2
library/ghost:6.65.090592b712b6b
ip-address@10.1.0
10.7.1
2
library/mongo-express:1.0.2:latest1b23d7976f02
ip-address@9.0.5
10.7.1
2
library/node:24.21.0-alpine3.239ec4a2e28987
ip-address@10.2.0
10.7.1
2
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.1.0
10.7.1
2
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.7.1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.1.0
10.7.1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.7.1
2
louislam/uptime-kuma:2.5.5c74379ac4509
ip-address@10.7.0
10.7.1
2
mojaloop/reporting:v12.1.0d480a62103d6
ip-address@9.0.5
10.7.1
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
ip-address@9.0.5
10.7.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ip-address@9.0.5
10.7.1
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
ip-address@9.0.5
10.7.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ip-address@9.0.5
10.7.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ip-address@10.0.1
10.7.1
2
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.7.1
2
nodered/node-red:5.0.7:latesta649dd711d55
ip-address@10.2.0
10.7.1
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.7.1
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
ip-address@6.4.0
10.7.1
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.7.1
2
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.7.1
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.7.1
2
requarks/wiki:2:latest68f0d1848261
ip-address@5.9.4
10.7.1
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.7.1
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
ip-address@9.0.5
10.7.1
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
ip-address@9.0.5
10.7.1
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ip-address@6.1.0
10.7.1
2
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.7.1
2
ghcr.io/advplyr/audiobookshelf:2.37.06432d1dc5895
ip-address@10.2.0
10.7.1
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
ip-address@10.5.0
10.7.1
2

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.