StackRadar

CVE-2026-101912

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
567
of 17,957 indexed, latest versions
Container images
573
deployed by those charts
Fix available
1 of 1
affected package

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Carried by container images the latest versions of 567 of 17,957 indexed charts deploy, on 573 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+11 more10.7.1573
OSV records
GHSA-j6r3-76f7-8jcv
Trending
Rank 24 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

567 by stars
ChartLatestAffected imagesRadar Score
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.7.1

Open the chart page →

74,963
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.7.1

Open the chart page →

2,105
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.7.1

Open the chart page →

3,149
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.7.1

Open the chart page →

7,480
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.7.1

Open the chart page →

6,197
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.7.1

Open the chart page →

5,967
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.7.1

Open the chart page →

1,606
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.7.1

Open the chart page →

4,129
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.7.1

Open the chart page →

1,934
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
ip-address@10.5.0
10.7.1

Open the chart page →

110
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.7.1

Open the chart page →

303
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.7.1

Open the chart page →

3,876
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.7.1

Open the chart page →

14,991
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101912.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.7.1

Open the chart page →

9,791

Container images carrying it

573 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
ip-address@9.0.5
10.7.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.7.1
1
ghcr.io/automation64/toolbox/oraclelinux-9-toolbox:latest7af2216c7b9e
ip-address@10.2.0
10.7.1
1
ghcr.io/backstage/backstage:lateste2a48bb6ab55
ip-address@10.2.0
10.7.1
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
ip-address@9.0.5
10.7.1
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
ip-address@9.0.5
10.7.1
1
ghcr.io/bluesky-social/pds:0.405e164855fa1
ip-address@10.2.0
10.7.1
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.7.1
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ip-address@9.0.5
10.7.1
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
ip-address@10.5.0
10.7.1
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.7.1
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.7.1
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.7.1
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
ip-address@9.0.5
10.7.1
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
ip-address@9.0.5
10.7.1
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.7.1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ip-address@9.0.5
10.7.1
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.7.1
1
ghcr.io/cameri/nostream:mainc134ac2fa289
ip-address@10.1.0
10.7.1
1
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.7.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.7.1
1
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.7.1
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.7.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ip-address@9.0.5
10.7.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
ip-address@9.0.5
10.7.1
1
ghcr.io/data-fair/notify:3c739b74dabb0
ip-address@9.0.5
10.7.1
1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.7.1
1
ghcr.io/devops-dojo7/fauxgpu/web:0.2.4691dd15d6bca
ip-address@10.1.0
10.7.1
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.7.1
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.7.1
1
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.7.1
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.7.1
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
ip-address@9.0.5
10.7.1
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
ip-address@9.0.5
10.7.1
1
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.1.0
10.7.1
1
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.7.1
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.7.1
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.7.1
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.7.1
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.7.1
1
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.7.1
1
ghcr.io/gethomepage/homepage:v1.11.0b129cb0f674b
ip-address@9.0.5
10.7.1
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
ip-address@10.1.0
10.7.1
1
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
ip-address@9.0.5
10.7.1
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
ip-address@10.1.0
10.7.1
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.7.1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.7.1
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.7.1
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.7.1
1
ghcr.io/immich-app/immich-server:v3.2.4d317916b2809
ip-address@10.2.0
10.7.1
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.