StackRadar

CVE-2026-101912

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-j6r3-76f7-8jcv
Trending
Rank 24 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
ip-address@9.0.5
10.7.1
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
ip-address@10.5.0
10.7.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.7.1
1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.7.1
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
ip-address@9.0.5
10.7.1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
ip-address@9.0.5
10.7.1
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.7.1
1
ghcr.io/seerr-team/seerr:v3.5.027602401178d
ip-address@9.0.5
10.7.1
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
ip-address@9.0.5
10.7.1
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
ip-address@10.1.0
10.7.1
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
ip-address@10.0.1
10.7.1
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
ip-address@10.7.0
10.7.1
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
ip-address@9.0.5
10.7.1
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
ip-address@9.0.5
10.7.1
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.7.1
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.9.162614fd45986
ip-address@10.1.1
10.7.1
1
ghcr.io/thm-mni-ii/fbs-collab:v2.0.1366bc4ec1079
ip-address@10.1.0
10.7.1
1
ghcr.io/thm-mni-ii/fbs-qcm-backend:v2.0.12633b7c61fb1
ip-address@9.0.5
10.7.1
1
ghcr.io/thm-mni-ii/fbs-qcm-frontend:v2.0.128c98d86ed77
ip-address@9.0.5
10.7.1
1
ghcr.io/thotischner/observability-mcp:3.9.11775e1e84d5d1
ip-address@10.3.1
10.7.1
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.4.0
10.7.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
ip-address@9.0.5
10.7.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
ip-address@9.0.5
10.7.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
ip-address@9.0.5
10.7.1
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
ip-address@10.1.0
10.7.1
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
ip-address@9.0.5
10.7.1
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
ip-address@10.1.0
10.7.1
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
ip-address@10.1.0
10.7.1
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
ip-address@10.0.1
10.7.1
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
ip-address@9.0.5
10.7.1
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.7.1
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
ip-address@9.0.5
10.7.1
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
ip-address@9.0.5
10.7.1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
ip-address@9.0.5
10.7.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
ip-address@9.0.5
10.7.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
ip-address@9.0.5
10.7.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
ip-address@10.1.0
10.7.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
ip-address@9.0.5
10.7.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
ip-address@9.0.5
10.7.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
ip-address@10.1.0
10.7.1
1
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
ip-address@9.0.5
10.7.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
ip-address@10.1.0
10.7.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.7.1
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
ip-address@9.0.5
10.7.1
1
public.ecr.aws/jtekt-corporation/api-key-manager-api:v0.1.175a48d987e0f
ip-address@10.2.0
10.7.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.7.1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.7.1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
ip-address@9.0.5
10.7.1
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ip-address@6.4.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.