StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.5.1
2
ghcr.io/gethomepage/homepage:latest:v2.4.0643bd0be730d
ip-address@10.5.0
10.5.1
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.5.1
2
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
ip-address@10.5.0
10.5.1
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.1.0
10.5.1
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
ip-address@9.0.5
10.5.1
2
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
ip-address@10.2.0
10.5.1
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
ip-address@10.2.0
10.5.1
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
ip-address@9.0.5
10.5.1
2
aaronshaf/dynamodb-admin:latestac41724cd997
ip-address@10.1.0
10.5.1
1
activepieces/activepieces:0.91.058414dfc94c4
ip-address@10.1.0
10.5.1
1
activepieces/activepieces:0.28.0a12efde0c535
ip-address@9.0.5
10.5.1
1
activepieces/activepieces:0.23.0c26188b44e62
ip-address@9.0.5
10.5.1
1
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.5.1
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
ip-address@10.0.1
10.5.1
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
ip-address@9.0.5
10.5.1
1
agentarea/agentarea-frontend:latest58e492779455
ip-address@10.1.0
10.5.1
1
agentarea/agentarea-mcp-runner:latest615da5917632
ip-address@10.1.0
10.5.1
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.5.1
1
alazidis/stornx:1.1.1602d4f7f090c
ip-address@9.0.5
10.5.1
1
alquimiaai/studio:certification38a1f0341982
ip-address@9.0.5
10.5.1
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
ip-address@9.0.5
10.5.1
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
ip-address@9.0.5
10.5.1
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
ip-address@10.1.0
10.5.1
1
arbuzov/claude-code-api:0.1.02d7dd8070610
ip-address@9.0.5
10.5.1
1
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.0.1
10.5.1
1
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.5.1
1
baserow/baserow:1.30.1df0c42eb67e8
ip-address@9.0.5
10.5.1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
ip-address@9.0.5
10.5.1
1
bluerange/bluerange-mosquitto:2690a4e5b92cc6
ip-address@10.4.0
10.5.1
1
bnjbvr/kresus:0.22.137e216b182c8
ip-address@9.0.5
10.5.1
1
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.5.1
1
budibase/database:2.1.0d90f656261c9
ip-address@10.1.0
10.5.1
1
budibase/worker:3.41.3de5e2e560ce8
ip-address@10.1.0
10.5.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
ip-address@9.0.5
10.5.1
1
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.5.1
1
cccs/assemblyline-ui-frontend:4.7.4.stable21c00e72d90666
ip-address@10.1.0
10.5.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
ip-address@9.0.5
10.5.1
1
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.5.1
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip-address@9.0.5
10.5.1
1
chatwoot/chatwoot:v4.16.2f9b071ffe678
ip-address@10.2.0
10.5.1
1
chibisafe/chibisafe:latest836467a50792
ip-address@9.0.5
10.5.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
ip-address@9.0.5
10.5.1
1
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.5.1
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
ip-address@9.0.5
10.5.1
1
codetogether/codetogether:latest4348c8a38752
ip-address@9.0.5
10.5.1
1
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
ip-address@10.1.0
10.5.1
1
contane/foreman:0.5.2efb98bdcc4e9
ip-address@9.0.5
10.5.1
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.5.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.