StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
opencloudcommunity-opencloud3.1.01 of 13See more

opencloud community-opencloud 3.1.0

1 of the 13 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.5.1

Open the chart page →

9,829
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.5.1

Open the chart page →

1,730
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.5.1

Open the chart page →

1,686
cortezacorteza1.1.01 of 3See more

corteza corteza 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.5.1

Open the chart page →

8,868
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.5.1

Open the chart page →

15,508
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
ip-address@6.4.0
10.5.1

Open the chart page →

14,397
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
cspconsole/report-processor:1.0.279a2d8840bfdf
ip-address@10.1.0
10.5.1

Open the chart page →

13,010
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.5.1

Open the chart page →

592
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.5.1

Open the chart page →

23,176
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.5.1

Open the chart page →

6,571
dbgatedbgate-helm-chartVerified publisher0.1.81 of 1See more

dbgate dbgate-helm-chart 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.3f2dc7423ea88
ip-address@10.1.0
10.5.1

Open the chart page →

1,544
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

280
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

280
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

280
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.02 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
decisionrules/business-intelligence:latest45a54ef6ade6
ip-address@10.1.0
10.5.1
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1

Open the chart page →

1,525
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
ip-address@9.0.5
10.5.1

Open the chart page →

4,705
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.5.1

Open the chart page →

1,621
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.5.1

Open the chart page →

2,581
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
ip-address@9.0.5
10.5.1

Open the chart page →

1,304
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ip-address@10.0.1
10.5.1

Open the chart page →

71,259
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ip-address@10.0.1
10.5.1

Open the chart page →

71,259
dial-admindialVerified publisher0.19.01 of 3See more

dial-admin dial 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.21.01ecee9f1aa09
ip-address@10.4.0
10.5.1

Open the chart page →

3,846
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.5.1

Open the chart page →

56,138
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
ip-address@9.0.5
10.5.1

Open the chart page →

4,754
node-reddjdl-charts0.33.01 of 1See more

node-red djdl-charts 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nodered/node-red:latesta649dd711d55
ip-address@10.2.0
10.5.1

Open the chart page →

156
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.5.1

Open the chart page →

7,928
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.5.1

Open the chart page →

4,366
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
ip-address@9.0.5
10.5.1

Open the chart page →

2,746
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-101913.

Open the chart page →

4,439
clickhouse-monitoringduyet0.1.31 of 2See more

clickhouse-monitoring duyet 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.5.1

Open the chart page →

1,093
dyff-frontenddyff-frontendVerified publisher0.20.21 of 1See more

dyff-frontend dyff-frontend 0.20.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
ip-address@9.0.5
10.5.1

Open the chart page →

1,180
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.5.1

Open the chart page →

744
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
ip-address@9.0.5
10.5.1

Open the chart page →

2,558
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
ip-address@9.0.5
10.5.1

Open the chart page →

1,494
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.5.1

Open the chart page →

1,105
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.5.1

Open the chart page →

32,092
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.5.1

Open the chart page →

3,416
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
ip-address@10.1.0
10.5.1

Open the chart page →

411
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@9.0.5
10.5.1

Open the chart page →

2,184
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@9.0.5
10.5.1

Open the chart page →

888
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ip-address@10.1.0
10.5.1

Open the chart page →

1,899
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.5.1

Open the chart page →

2,927
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
ip-address@5.9.4
10.5.1

Open the chart page →

1,135
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
chainsafe/lodestar:latestd717e4193699
ip-address@10.2.0
10.5.1

Open the chart page →

2,670
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1

Open the chart page →

7,377
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
ip-address@9.0.5
10.5.1

Open the chart page →

993
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1

Open the chart page →

7,377
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.5.1

Open the chart page →

6,195
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
ip-address@10.1.0
10.5.1

Open the chart page →

5,971
fauxgpufauxgpuVerified publisher0.2.41 of 4See more

fauxgpu fauxgpu 0.2.4

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/devops-dojo7/fauxgpu/web:0.2.4691dd15d6bca
ip-address@10.1.0
10.5.1

Open the chart page →

3,037

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gethue/hue:latest7d5c1b9f8a79
ip-address@10.1.0
10.5.1
1
getwud/wud:8.1.1b1cd01c43839
ip-address@9.0.5
10.5.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.5.1
1
globalping/globalping-probe:latestb8469caf783a
ip-address@10.1.0
10.5.1
1
growthbook/growthbook:5.1.0c8a124f55dca
ip-address@10.5.0
10.5.1
1
growthbook/growthbook:latestcbf1bc59e9a9
ip-address@10.5.0
10.5.1
1
haohanyang/compass-web:0.5.054f2112602ee
ip-address@10.1.0
10.5.1
1
haohanyang/compass-web:0.1.1e3952b14ae8e
ip-address@9.0.5
10.5.1
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.5.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ip-address@9.0.5
10.5.1
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.5.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ip-address@9.0.5
10.5.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.5.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.5.1
1
hoppscotch/hoppscotch:2026.8.2e7ba6061a286
ip-address@10.5.0
10.5.1
1
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.5.1
1
infisical/infisical:latest:v0.165.602082bf13163
ip-address@9.0.5
10.5.1
1
infisical/infisical:latest3365445909be
ip-address@10.1.0
10.5.1
1
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.5.1
1
iwakitakuma/gitlab-mcp:2.0.7fb3e81aa6528
ip-address@9.0.5
10.5.1
1
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.5.1
1
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.5.1
1
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.5.1
1
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.5.1
1
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.5.1
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.5.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.5.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.5.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.5.1
1
journeyapps/powersync-service:latest413a0c813e96
ip-address@10.2.0
10.5.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.5.1
1
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.5.1
1
kitware/cdash:v5.4.0da5abe941506
ip-address@10.2.0
10.5.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.5.1
1
laituanmanh/websearch-crawler:latest63b6da557c71
ip-address@9.0.5
10.5.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.5.1
1
langflowai/langflow:1.12.334055a07d446
ip-address@10.3.1
10.5.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.5.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.5.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.5.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.5.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.5.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.5.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.5.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.5.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.5.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.5.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.5.1
1
letsbootch/argocd-game2048-app:1.0.0288abd32b2b7
ip-address@9.0.5
10.5.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.