StackRadar

CVE-2026-101912

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-j6r3-76f7-8jcv
Trending
Rank 24 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.7.1

Open the chart page →

2,752
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.7.1

Open the chart page →

7,570
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
ip-address@9.0.5
10.7.1

Open the chart page →

1,046
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.7.1

Open the chart page →

7,570
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.7.1

Open the chart page →

6,440
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
ip-address@10.1.0
10.7.1

Open the chart page →

6,053
fauxgpufauxgpuVerified publisher0.2.41 of 4See more

fauxgpu fauxgpu 0.2.4

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/devops-dojo7/fauxgpu/web:0.2.4691dd15d6bca
ip-address@10.1.0
10.7.1

Open the chart page →

3,231
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip-address@9.0.5
10.7.1

Open the chart page →

8,182
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip-address@9.0.5
10.7.1

Open the chart page →

118,495
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.7.1

Open the chart page →

2,163
fdsc-dashboardfiware0.6.101 of 1See more

fdsc-dashboard fiware 0.6.10

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
quay.io/seamware/fdsc-dashboard:0.6.51b02c5685f01
ip-address@9.0.5
10.7.1

Open the chart page →

792
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.7.1

Open the chart page →

1,738
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
ip-address@9.0.5
10.7.1

Open the chart page →

4,878
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.1.0
10.7.1

Open the chart page →

23,036
flanksource-uiflanksourceVerified publisher1.4.3201 of 1See more

flanksource-ui flanksource 1.4.320

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
ip-address@9.0.5
10.7.1

Open the chart page →

2,784
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.7.1

Open the chart page →

9,535
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
ip-address@10.0.1
10.7.1

Open the chart page →

3,748
fluxer-helmfluxer-helm0.3.01 of 18See more

fluxer-helm fluxer-helm 0.3.0

1 of the 18 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.7.1

Open the chart page →

29,747
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
ip-address@9.0.5
10.7.1

Open the chart page →

3,486
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
ip-address@9.0.5
10.7.1

Open the chart page →

3,509
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.7.1

Open the chart page →

4,465
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
ip-address@9.0.5
10.7.1

Open the chart page →

1,088
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
ip-address@9.0.5
10.7.1

Open the chart page →

5,059
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
ip-address@9.0.5
10.7.1
frinx/frinx-inventory-server:7.0.16b1992c79e78
ip-address@9.0.5
10.7.1

Open the chart page →

44,552
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
ip-address@9.0.5
10.7.1

Open the chart page →

4,903
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
ip-address@9.0.5
10.7.1

Open the chart page →

994
garge-appgargeVerified publisher0.1.531 of 1See more

garge-app garge 0.1.53

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.7.1

Open the chart page →

788
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.7.1

Open the chart page →

2,080
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.7.1

Open the chart page →

14,062
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.7.1

Open the chart page →

2,080
genieacsgenieacsVerified publisher0.5.21 of 2See more

genieacs genieacs 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.6ffbf8bd1340d
ip-address@10.1.0
10.7.1

Open the chart page →

3,740
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.7.1

Open the chart page →

3,229
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.7.1

Open the chart page →

1,298
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
ip-address@9.0.5
10.7.1

Open the chart page →

12,534
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
ip-address@9.0.5
10.7.1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
ip-address@9.0.5
10.7.1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
ip-address@9.0.5
10.7.1

Open the chart page →

52,401
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ip-address@9.0.5
10.7.1

Open the chart page →

3,366
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.1.0
10.7.1

Open the chart page →

7,612
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.7.1

Open the chart page →

4,110
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.7.1

Open the chart page →

1,052
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.7.1

Open the chart page →

3,663
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.7.1

Open the chart page →

949
affinehelmforgeVerified publisher1.0.11 of 3See more

affine helmforge 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.4.0
10.7.1

Open the chart page →

4,221
archiveboxhelmforgeVerified publisher1.1.131 of 1See more

archivebox helmforge 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.0.1
10.7.1

Open the chart page →

5,534
automatischhelmforgeVerified publisher1.3.81 of 4See more

automatisch helmforge 1.3.8

1 of the 4 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.7.1

Open the chart page →

5,682
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.7.1

Open the chart page →

77,505
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.7.1

Open the chart page →

1,601
ghosthelmforgeVerified publisher1.2.101 of 3See more

ghost helmforge 1.2.10

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
ip-address@10.1.0
10.7.1

Open the chart page →

2,760
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.7.1

Open the chart page →

6,076
homarrhelmforgeVerified publisher1.2.111 of 1See more

homarr helmforge 1.2.11

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.7.1

Open the chart page →

614
hoppscotchhelmforgeVerified publisher1.1.121 of 2See more

hoppscotch helmforge 1.1.12

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.7.1

Open the chart page →

1,911

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
ip-address@9.0.5
10.7.1
1
fthomas/scala-steward:latesta8eb43927576
ip-address@10.1.0
10.7.1
1
gethue/hue:latest7d5c1b9f8a79
ip-address@10.1.0
10.7.1
1
getwud/wud:8.1.1b1cd01c43839
ip-address@9.0.5
10.7.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.7.1
1
globalping/globalping-probe:latestb8469caf783a
ip-address@10.1.0
10.7.1
1
growthbook/growthbook:5.1.0c8a124f55dca
ip-address@10.5.0
10.7.1
1
growthbook/growthbook:latestcbf1bc59e9a9
ip-address@10.5.0
10.7.1
1
haohanyang/compass-web:0.5.054f2112602ee
ip-address@10.1.0
10.7.1
1
haohanyang/compass-web:0.1.1e3952b14ae8e
ip-address@9.0.5
10.7.1
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.7.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ip-address@9.0.5
10.7.1
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.7.1
1
helmforge/strapi-base:5.52.270e9143d6d92
ip-address@10.7.0
10.7.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ip-address@9.0.5
10.7.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.7.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.7.1
1
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.7.1
1
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.7.1
1
infisical/infisical:latest:v0.165.602082bf13163
ip-address@9.0.5
10.7.1
1
infisical/infisical:latest3365445909be
ip-address@10.7.0
10.7.1
1
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.7.1
1
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
ip-address@9.0.5
10.7.1
1
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.7.1
1
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.7.1
1
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.7.1
1
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.7.1
1
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.7.1
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.7.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.7.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.7.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.7.1
1
journeyapps/powersync-service:latest413a0c813e96
ip-address@10.2.0
10.7.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.7.1
1
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1
1
kitware/cdash:v5.4.0da5abe941506
ip-address@10.2.0
10.7.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.7.1
1
laituanmanh/websearch-crawler:latest63b6da557c71
ip-address@9.0.5
10.7.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.7.1
1
langflowai/langflow:1.12.334055a07d446
ip-address@10.3.1
10.7.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.7.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.7.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.7.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.7.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.7.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.7.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.7.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.7.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.7.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.