StackRadar

CVE-2026-101912

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-j6r3-76f7-8jcv
Trending
Rank 24 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nocodb/nocodb:latest4ccfc5114506
ip-address@10.7.0
10.7.1
1
nocodb/nocodb:0.258.06779a4ddedf2
ip-address@9.0.5
10.7.1
1
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.7.1
1
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.7.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.7.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.7.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.7.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.7.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.7.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.7.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.7.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.7.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.7.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.7.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.7.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.7.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.7.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.7.1
1
oneuptime/probe:release2a170032aee8
ip-address@10.7.0
10.7.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.7.1
1
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.7.1
1
opencti/platform:7.260928.1d40cdb191cd0
ip-address@10.1.0
10.7.1
1
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.7.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.7.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.7.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.7.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.7.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.7.1
1
otwld/velero-ui:0.10.31c228d9ef71b
ip-address@10.1.0
10.7.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.7.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.7.1
1
penpotapp/exporter:2.2.15c835ffd87ab
ip-address@9.0.5
10.7.1
1
penpotapp/exporter:2.18.0beb2c2bd9660
ip-address@10.3.1
10.7.1
1
penpotapp/mcp:2.18.09270da9fab95
ip-address@10.5.0
10.7.1
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
ip-address@10.0.1
10.7.1
1
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.7.1
1
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.7.1
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
ip-address@10.0.1
10.7.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
ip-address@9.0.5
10.7.1
1
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.7.1
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.7.1
1
redis/redisinsight:2.68019fcf774631
ip-address@9.0.5
10.7.1
1
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.7.1
1
redis/redisinsight:2.46699d341bd329
ip-address@9.0.5
10.7.1
1
redis/redisinsight:3.485562d67a912
ip-address@9.0.5
10.7.1
1
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.7.1
1
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
ip-address@10.1.0
10.7.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.