StackRadar

CVE-2026-101912

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-j6r3-76f7-8jcv
Trending
Rank 24 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.7.1

Open the chart page →

2,752
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.7.1

Open the chart page →

7,570
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
ip-address@9.0.5
10.7.1

Open the chart page →

1,046
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.7.1

Open the chart page →

7,570
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.7.1

Open the chart page →

6,440
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
ip-address@10.1.0
10.7.1

Open the chart page →

6,053
fauxgpufauxgpuVerified publisher0.2.41 of 4See more

fauxgpu fauxgpu 0.2.4

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/devops-dojo7/fauxgpu/web:0.2.4691dd15d6bca
ip-address@10.1.0
10.7.1

Open the chart page →

3,231
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip-address@9.0.5
10.7.1

Open the chart page →

8,182
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip-address@9.0.5
10.7.1

Open the chart page →

118,495
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.7.1

Open the chart page →

2,163
fdsc-dashboardfiware0.6.101 of 1See more

fdsc-dashboard fiware 0.6.10

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
quay.io/seamware/fdsc-dashboard:0.6.51b02c5685f01
ip-address@9.0.5
10.7.1

Open the chart page →

792
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.7.1

Open the chart page →

1,738
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
ip-address@9.0.5
10.7.1

Open the chart page →

4,878
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.1.0
10.7.1

Open the chart page →

23,036
flanksource-uiflanksourceVerified publisher1.4.3201 of 1See more

flanksource-ui flanksource 1.4.320

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
ip-address@9.0.5
10.7.1

Open the chart page →

2,784
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.7.1

Open the chart page →

9,535
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
ip-address@10.0.1
10.7.1

Open the chart page →

3,748
fluxer-helmfluxer-helm0.3.01 of 18See more

fluxer-helm fluxer-helm 0.3.0

1 of the 18 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.7.1

Open the chart page →

29,747
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
ip-address@9.0.5
10.7.1

Open the chart page →

3,486
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
ip-address@9.0.5
10.7.1

Open the chart page →

3,509
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.7.1

Open the chart page →

4,465
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
ip-address@9.0.5
10.7.1

Open the chart page →

1,088
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
ip-address@9.0.5
10.7.1

Open the chart page →

5,059
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
ip-address@9.0.5
10.7.1
frinx/frinx-inventory-server:7.0.16b1992c79e78
ip-address@9.0.5
10.7.1

Open the chart page →

44,552
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
ip-address@9.0.5
10.7.1

Open the chart page →

4,903
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
ip-address@9.0.5
10.7.1

Open the chart page →

994
garge-appgargeVerified publisher0.1.531 of 1See more

garge-app garge 0.1.53

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.7.1

Open the chart page →

788
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.7.1

Open the chart page →

2,080
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.7.1

Open the chart page →

14,062
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.7.1

Open the chart page →

2,080
genieacsgenieacsVerified publisher0.5.21 of 2See more

genieacs genieacs 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.6ffbf8bd1340d
ip-address@10.1.0
10.7.1

Open the chart page →

3,740
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.7.1

Open the chart page →

3,229
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.7.1

Open the chart page →

1,298
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
ip-address@9.0.5
10.7.1

Open the chart page →

12,534
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
ip-address@9.0.5
10.7.1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
ip-address@9.0.5
10.7.1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
ip-address@9.0.5
10.7.1

Open the chart page →

52,401
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ip-address@9.0.5
10.7.1

Open the chart page →

3,366
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.1.0
10.7.1

Open the chart page →

7,612
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.7.1

Open the chart page →

4,110
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.7.1

Open the chart page →

1,052
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.7.1

Open the chart page →

3,663
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.7.1

Open the chart page →

949
affinehelmforgeVerified publisher1.0.11 of 3See more

affine helmforge 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.4.0
10.7.1

Open the chart page →

4,221
archiveboxhelmforgeVerified publisher1.1.131 of 1See more

archivebox helmforge 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.0.1
10.7.1

Open the chart page →

5,534
automatischhelmforgeVerified publisher1.3.81 of 4See more

automatisch helmforge 1.3.8

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.7.1

Open the chart page →

5,682
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.7.1

Open the chart page →

77,505
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.7.1

Open the chart page →

1,601
ghosthelmforgeVerified publisher1.2.101 of 3See more

ghost helmforge 1.2.10

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
ip-address@10.1.0
10.7.1

Open the chart page →

2,760
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.7.1

Open the chart page →

6,076
homarrhelmforgeVerified publisher1.2.111 of 1See more

homarr helmforge 1.2.11

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.7.1

Open the chart page →

614
hoppscotchhelmforgeVerified publisher1.1.121 of 2See more

hoppscotch helmforge 1.1.12

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.7.1

Open the chart page →

1,911

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ip-address@10.1.0
10.7.1
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.7.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
ip-address@10.1.0
10.7.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
ip-address@10.1.0
10.7.1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
ip-address@9.0.5
10.7.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
ip-address@9.0.5
10.7.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
ip-address@10.4.0
10.7.1
1
quay.io/seamware/fdsc-dashboard:0.6.51b02c5685f01
ip-address@9.0.5
10.7.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.7.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.7.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.7.1
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
ip-address@9.0.5
10.7.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
ip-address@10.1.0
10.7.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ip-address@10.1.0
10.7.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
ip-address@10.1.0
10.7.1
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
ip-address@10.1.0
10.7.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
ip-address@10.5.0
10.7.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
ip-address@10.5.0
10.7.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
ip-address@10.5.0
10.7.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
ip-address@10.5.0
10.7.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
ip-address@10.4.0
10.7.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.7.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.94.09d9860c05c39
ip-address@10.2.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.