StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
countly/api:25.05.4f4cc7447c4f5
ip-address@5.9.4
10.5.1
1
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.5.1
1
countly/frontend:25.05.42acbc11499b6
ip-address@5.9.4
10.5.1
1
cspconsole/report-processor:1.0.279a2d8840bfdf
ip-address@10.1.0
10.5.1
1
cyfershepard/jellystat:1.1.12e61c759ec706
ip-address@10.2.0
10.5.1
1
dbgate/dbgate:7.2.0-alpine287077002446
ip-address@9.0.5
10.5.1
1
dbgate/dbgate:7.2.3f2dc7423ea88
ip-address@10.1.0
10.5.1
1
decisionrules/business-intelligence:latest45a54ef6ade6
ip-address@10.1.0
10.5.1
1
defactops/defactops-backend:1.0.2307b663c0092a
ip-address@9.0.5
10.5.1
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip-address@10.2.0
10.5.1
1
devkrishan001/backend:latestf1c3acadeabe
ip-address@9.0.5
10.5.1
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.5.1
1
devravinder/node-express-app:1.0.05325a96967b5
ip-address@9.0.5
10.5.1
1
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.5.1
1
directus/directus:11.1.0e3c8bb975350
ip-address@9.0.5
10.5.1
1
diygod/rsshub:latest22845ada2f14
ip-address@10.2.0
10.5.1
1
diygod/rsshub:2025-11-097a6312cac0d5
ip-address@10.0.1
10.5.1
1
docmost/docmost:0.96.0b56947fcfd08
ip-address@10.3.1
10.5.1
1
documenso/documenso:v1.8.17f16a9449f18
ip-address@9.0.5
10.5.1
1
drumsergio/genieacs:1.2.16.028244054e1bf
ip-address@10.1.0
10.5.1
1
drumsergio/lynxprompt:2.0.75c6afb6679301
ip-address@10.1.0
10.5.1
1
drumsergio/pumperly:1.4.885bbc3915e9e
ip-address@10.1.0
10.5.1
1
ducktors/turborepo-remote-cache:latest8aa1c158d885
ip-address@10.2.0
10.5.1
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.5.1
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
ip-address@9.0.5
10.5.1
1
epam/ai-dial-admin-frontend:0.21.01ecee9f1aa09
ip-address@10.4.0
10.5.1
1
epam/ai-dial-chat:1.1.0974c1ddceab6
ip-address@10.5.0
10.5.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ip-address@9.0.5
10.5.1
1
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.5.1
1
ethpandaops/ethereumjs:masterfb84b718500f
ip-address@9.0.5
10.5.1
1
evershop/evershop:latestd0823576f91b
ip-address@9.0.5
10.5.1
1
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.5.1
1
fallenbagel/jellyseerr:latest4538137bc5af
ip-address@9.0.5
10.5.1
1
fallenbagel/jellyseerr:2.2.3a324fa4d81cc
ip-address@9.0.5
10.5.1
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
ip-address@9.0.5
10.5.1
1
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.5.1
1
felipecs8/landing-page:v1db6d44e325a1
ip-address@9.0.5
10.5.1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip-address@9.0.5
10.5.1
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
ip-address@9.0.5
10.5.1
1
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
ip-address@9.0.5
10.5.1
1
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.5.1
1
folioci/mod-graphql:latestf0655a6a08fd
ip-address@9.0.5
10.5.1
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
ip-address@9.0.5
10.5.1
1
fosrl/pangolin:latest00cfb631097a
ip-address@10.2.0
10.5.1
1
fosrl/pangolin:1.13.0c32ad797ab96
ip-address@10.0.1
10.5.1
1
frinx/frinx-graphql-proxy:7.0.017a139608024
ip-address@9.0.5
10.5.1
1
frinx/frinx-graphql-proxy:6.1.05f1368ef47b8
ip-address@9.0.5
10.5.1
1
frinx/frinx-inventory-server:7.0.16b1992c79e78
ip-address@9.0.5
10.5.1
1
frinx/frinx-inventory-server:6.1.086c9ce1f5e31
ip-address@9.0.5
10.5.1
1
fthomas/scala-steward:latesta8eb43927576
ip-address@10.1.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.