StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gethue/hue:latest7d5c1b9f8a79
ip-address@10.1.0
10.5.1
1
getwud/wud:8.1.1b1cd01c43839
ip-address@9.0.5
10.5.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.5.1
1
globalping/globalping-probe:latestb8469caf783a
ip-address@10.1.0
10.5.1
1
growthbook/growthbook:5.1.0c8a124f55dca
ip-address@10.5.0
10.5.1
1
growthbook/growthbook:latestcbf1bc59e9a9
ip-address@10.5.0
10.5.1
1
haohanyang/compass-web:0.5.054f2112602ee
ip-address@10.1.0
10.5.1
1
haohanyang/compass-web:0.1.1e3952b14ae8e
ip-address@9.0.5
10.5.1
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.5.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ip-address@9.0.5
10.5.1
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.5.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ip-address@9.0.5
10.5.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.5.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.5.1
1
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.5.1
1
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.5.1
1
infisical/infisical:latest:v0.165.602082bf13163
ip-address@9.0.5
10.5.1
1
infisical/infisical:latest3365445909be
ip-address@10.1.0
10.5.1
1
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.5.1
1
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
ip-address@9.0.5
10.5.1
1
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.5.1
1
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.5.1
1
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.5.1
1
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.5.1
1
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.5.1
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.5.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.5.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.5.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.5.1
1
journeyapps/powersync-service:latest413a0c813e96
ip-address@10.2.0
10.5.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.5.1
1
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.5.1
1
kitware/cdash:v5.4.0da5abe941506
ip-address@10.2.0
10.5.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.5.1
1
laituanmanh/websearch-crawler:latest63b6da557c71
ip-address@9.0.5
10.5.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.5.1
1
langflowai/langflow:1.12.334055a07d446
ip-address@10.3.1
10.5.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.5.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.5.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.5.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.5.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.5.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.5.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.5.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.5.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.5.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.5.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.5.1
1
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
ip-address@9.0.5
10.5.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.