StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
ip-address@9.0.5
10.5.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
ip-address@10.4.0
10.5.1
1
quay.io/seamware/fdsc-dashboard:0.6.51b02c5685f01
ip-address@9.0.5
10.5.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.5.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.5.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.5.1
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
ip-address@9.0.5
10.5.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
ip-address@10.1.0
10.5.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ip-address@10.1.0
10.5.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
ip-address@10.1.0
10.5.1
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
ip-address@10.1.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
ip-address@10.5.0
10.5.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:mainaa62b23f2b5e
ip-address@10.4.0
10.5.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.5.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.94.09d9860c05c39
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.