StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip-address@9.0.5
10.5.1

Open the chart page →

8,117
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip-address@9.0.5
10.5.1

Open the chart page →

118,033
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.5.1

Open the chart page →

2,066
fdsc-dashboardfiware0.6.101 of 1See more

fdsc-dashboard fiware 0.6.10

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/seamware/fdsc-dashboard:0.6.51b02c5685f01
ip-address@9.0.5
10.5.1

Open the chart page →

739
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.5.1

Open the chart page →

1,676
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
ip-address@9.0.5
10.5.1

Open the chart page →

4,827
facetflanksourceVerified publisher0.1.731 of 1See more

facet flanksource 0.1.73

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.1.0
10.5.1

Open the chart page →

22,454
flanksource-uiflanksourceVerified publisher1.4.3201 of 1See more

flanksource-ui flanksource 1.4.320

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
ip-address@9.0.5
10.5.1

Open the chart page →

2,734
mission-controlflanksourceVerified publisher0.1.3381 of 8See more

mission-control flanksource 0.1.338

1 of the 8 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.5.1

Open the chart page →

9,456
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
louislam/uptime-kuma:170233f4acb51
ip-address@10.0.1
10.5.1

Open the chart page →

3,627
fluxer-helmfluxer-helm0.3.01 of 18See more

fluxer-helm fluxer-helm 0.3.0

1 of the 18 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.5.1

Open the chart page →

29,230
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
ip-address@9.0.5
10.5.1

Open the chart page →

3,395
linkwardenfmjstudios0.3.61 of 2See more

linkwarden fmjstudios 0.3.6

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.5.398214faf09f7
ip-address@9.0.5
10.5.1

Open the chart page →

3,436
uptime-kumafmjstudios0.2.21 of 1See more

uptime-kuma fmjstudios 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.5.1

Open the chart page →

4,345
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
ip-address@9.0.5
10.5.1

Open the chart page →

1,088
frinx-frontendfrinx-helm-charts4.1.01 of 2See more

frinx-frontend frinx-helm-charts 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
ip-address@9.0.5
10.5.1

Open the chart page →

4,955
frinx-machinefrinx-helm-charts11.0.02 of 26See more

frinx-machine frinx-helm-charts 11.0.0

2 of the 26 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
frinx/frinx-graphql-proxy:7.0.017a139608024
ip-address@9.0.5
10.5.1
frinx/frinx-inventory-server:7.0.16b1992c79e78
ip-address@9.0.5
10.5.1

Open the chart page →

44,191
inventoryfrinx-helm-charts6.0.21 of 4See more

inventory frinx-helm-charts 6.0.2

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
ip-address@9.0.5
10.5.1

Open the chart page →

4,830
game2048game20481.0.01 of 1See more

game2048 game2048 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
ip-address@9.0.5
10.5.1

Open the chart page →

941
garge-appgargeVerified publisher0.1.531 of 1See more

garge-app garge 0.1.53

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.5.1

Open the chart page →

646
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.5.1

Open the chart page →

2,026
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.5.1

Open the chart page →

13,962
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.5.1

Open the chart page →

2,026
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
ip-address@10.1.0
10.5.1

Open the chart page →

4,479
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.5.1

Open the chart page →

3,185
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.5.1

Open the chart page →

1,223
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
ip-address@9.0.5
10.5.1

Open the chart page →

12,364
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
ip-address@9.0.5
10.5.1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
ip-address@9.0.5
10.5.1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
ip-address@9.0.5
10.5.1

Open the chart page →

51,929
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ip-address@9.0.5
10.5.1

Open the chart page →

3,285
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.1.0
10.5.1

Open the chart page →

6,984
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.5.1

Open the chart page →

4,028
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.5.1

Open the chart page →

999
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.5.1

Open the chart page →

3,583
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.5.1

Open the chart page →

821
affinehelmforgeVerified publisher1.0.11 of 3See more

affine helmforge 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.4.0
10.5.1

Open the chart page →

4,030
archiveboxhelmforgeVerified publisher1.1.131 of 1See more

archivebox helmforge 1.1.13

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.0.1
10.5.1

Open the chart page →

5,365
automatischhelmforgeVerified publisher1.3.81 of 4See more

automatisch helmforge 1.3.8

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.5.1

Open the chart page →

5,469
countlyhelmforgeVerified publisher1.2.81 of 3See more

countly helmforge 1.2.8

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.5.1

Open the chart page →

77,199
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.5.1

Open the chart page →

1,513
ghosthelmforgeVerified publisher1.2.101 of 3See more

ghost helmforge 1.2.10

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
ip-address@10.1.0
10.5.1

Open the chart page →

2,591
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.5.1

Open the chart page →

5,766
homarrhelmforgeVerified publisher1.2.111 of 1See more

homarr helmforge 1.2.11

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.5.1

Open the chart page →

482
hoppscotchhelmforgeVerified publisher1.1.121 of 2See more

hoppscotch helmforge 1.1.12

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.5.1

Open the chart page →

1,736
immichhelmforgeVerified publisher1.2.91 of 5See more

immich helmforge 1.2.9

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.5.1

Open the chart page →

11,588
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
ip-address@10.3.1
10.5.1

Open the chart page →

95
matterbridgehelmforgeVerified publisher1.0.51 of 1See more

matterbridge helmforge 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.11e278cf685f91
ip-address@10.2.0
10.5.1

Open the chart page →

742
memoshelmforgeVerified publisher2.0.21 of 2See more

memos helmforge 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.239ec4a2e28987
ip-address@10.2.0
10.5.1

Open the chart page →

141
middlewarehelmforgeVerified publisher1.2.71 of 4See more

middleware helmforge 1.2.7

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.5.1

Open the chart page →

9,356
opencuthelmforgeVerified publisher1.1.101 of 5See more

opencut helmforge 1.1.10

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.5.1

Open the chart page →

3,090
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.5.1

Open the chart page →

2,795

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.5.1
2
ghcr.io/gethomepage/homepage:latest:v2.4.0643bd0be730d
ip-address@10.5.0
10.5.1
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.5.1
2
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
ip-address@10.5.0
10.5.1
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
ip-address@10.1.0
10.5.1
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
ip-address@9.0.5
10.5.1
2
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
ip-address@10.2.0
10.5.1
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
ip-address@10.2.0
10.5.1
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
ip-address@9.0.5
10.5.1
2
aaronshaf/dynamodb-admin:latestac41724cd997
ip-address@10.1.0
10.5.1
1
activepieces/activepieces:0.91.058414dfc94c4
ip-address@10.1.0
10.5.1
1
activepieces/activepieces:0.28.0a12efde0c535
ip-address@9.0.5
10.5.1
1
activepieces/activepieces:0.23.0c26188b44e62
ip-address@9.0.5
10.5.1
1
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.5.1
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
ip-address@10.0.1
10.5.1
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
ip-address@9.0.5
10.5.1
1
agentarea/agentarea-frontend:latest58e492779455
ip-address@10.1.0
10.5.1
1
agentarea/agentarea-mcp-runner:latest615da5917632
ip-address@10.1.0
10.5.1
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.5.1
1
alazidis/stornx:1.1.1602d4f7f090c
ip-address@9.0.5
10.5.1
1
alquimiaai/studio:certification38a1f0341982
ip-address@9.0.5
10.5.1
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
ip-address@9.0.5
10.5.1
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
ip-address@9.0.5
10.5.1
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
ip-address@10.1.0
10.5.1
1
arbuzov/claude-code-api:0.1.02d7dd8070610
ip-address@9.0.5
10.5.1
1
archivebox/archivebox:0.9.708c21bb233130
ip-address@10.0.1
10.5.1
1
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.5.1
1
baserow/baserow:1.30.1df0c42eb67e8
ip-address@9.0.5
10.5.1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
ip-address@9.0.5
10.5.1
1
bluerange/bluerange-mosquitto:2690a4e5b92cc6
ip-address@10.4.0
10.5.1
1
bnjbvr/kresus:0.22.137e216b182c8
ip-address@9.0.5
10.5.1
1
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.5.1
1
budibase/database:2.1.0d90f656261c9
ip-address@10.1.0
10.5.1
1
budibase/worker:3.41.3de5e2e560ce8
ip-address@10.1.0
10.5.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
ip-address@9.0.5
10.5.1
1
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.5.1
1
cccs/assemblyline-ui-frontend:4.7.4.stable21c00e72d90666
ip-address@10.1.0
10.5.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
ip-address@9.0.5
10.5.1
1
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.5.1
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
ip-address@9.0.5
10.5.1
1
chatwoot/chatwoot:v4.16.2f9b071ffe678
ip-address@10.2.0
10.5.1
1
chibisafe/chibisafe:latest836467a50792
ip-address@9.0.5
10.5.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
ip-address@9.0.5
10.5.1
1
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.5.1
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
ip-address@9.0.5
10.5.1
1
codetogether/codetogether:latest4348c8a38752
ip-address@9.0.5
10.5.1
1
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
ip-address@10.1.0
10.5.1
1
contane/foreman:0.5.2efb98bdcc4e9
ip-address@9.0.5
10.5.1
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.5.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.