StackRadar

CVE-2026-101912

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-j6r3-76f7-8jcv
Trending
Rank 24 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.7.1
1
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
ip-address@9.0.5
10.7.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.7.1
1
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.7.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.7.1
1
library/ghost:6.64.0586821cfebac
ip-address@10.1.0
10.7.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.7.1
1
library/ghost:6.65.0-alpine3.23fea3264f902e
ip-address@10.1.0
10.7.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.7.1
1
library/node:22-bookworm-slim48e4b67d85f8
ip-address@10.1.0
10.7.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.7.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.7.1
1
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.7.1
1
lissy93/domain-locker:latest58a903b2cdd9
ip-address@10.2.0
10.7.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.7.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.7.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.7.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.7.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.7.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.7.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.7.1
1
louislam/uptime-kuma:170233f4acb51
ip-address@10.0.1
10.7.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.7.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.7.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.7.1
1
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.7.1
1
luligu/matterbridge:3.10.11e278cf685f91
ip-address@10.2.0
10.7.1
1
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.7.1
1
mauricenino/dashdot:5.9.2236997816917
ip-address@9.0.5
10.7.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.7.1
1
mcp/kubernetes:latest5ffbf7f0a8aa
ip-address@10.2.0
10.7.1
1
mcpuse/inspector:latest4f23f55e7c96
ip-address@10.1.0
10.7.1
1
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.7.1
1
mishtinetwork/operator:latestbb3fe67a5f7c
ip-address@9.0.5
10.7.1
1
misskey/misskey:12.110.1e08b7c478093
ip-address@7.1.0
10.7.1
1
mitre/heimdall2:release-latest06f6e72d416a
ip-address@10.4.0
10.7.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.7.1
1
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.7.1
1
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.7.1
1
moreillon/food-manager:lateste8fd856e593d
ip-address@9.0.5
10.7.1
1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.7.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.7.1
1
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.7.1
1
n8nio/n8n:2.40.59f693fd55655
ip-address@10.3.1
10.7.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.3.1
10.7.1
1
n8nio/n8n:1.33.1dd171d45102a
ip-address@9.0.5
10.7.1
1
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.7.1
1
n8nio/n8n:2.41.3fdce8f852ac7
ip-address@10.3.1
10.7.1
1
neoskop/ixy:2.2.015a480e34778
ip-address@10.2.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.