StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.5.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.5.1
1
library/ghost:6.64.0586821cfebac
ip-address@10.1.0
10.5.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.5.1
1
library/ghost:6.65.0-alpine3.23fea3264f902e
ip-address@10.1.0
10.5.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.5.1
1
library/node:22-bookworm-slim48e4b67d85f8
ip-address@10.1.0
10.5.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.5.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.5.1
1
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.5.1
1
lissy93/domain-locker:latest58a903b2cdd9
ip-address@10.2.0
10.5.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.5.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.5.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.5.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.5.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.5.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.5.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.5.1
1
louislam/uptime-kuma:170233f4acb51
ip-address@10.0.1
10.5.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.5.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.5.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.5.1
1
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.5.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.5.1
1
luligu/matterbridge:3.10.11e278cf685f91
ip-address@10.2.0
10.5.1
1
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.5.1
1
mauricenino/dashdot:5.9.2236997816917
ip-address@9.0.5
10.5.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.5.1
1
mcp/kubernetes:latest5ffbf7f0a8aa
ip-address@10.2.0
10.5.1
1
mcpuse/inspector:latest4f23f55e7c96
ip-address@10.1.0
10.5.1
1
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.5.1
1
mishtinetwork/operator:latestbb3fe67a5f7c
ip-address@9.0.5
10.5.1
1
misskey/misskey:12.110.1e08b7c478093
ip-address@7.1.0
10.5.1
1
mitre/heimdall2:release-latest06f6e72d416a
ip-address@10.4.0
10.5.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.5.1
1
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.5.1
1
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.5.1
1
moreillon/food-manager:lateste8fd856e593d
ip-address@9.0.5
10.5.1
1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.5.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.5.1
1
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.5.1
1
n8nio/n8n:2.40.59f693fd55655
ip-address@10.3.1
10.5.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.3.1
10.5.1
1
n8nio/n8n:1.33.1dd171d45102a
ip-address@9.0.5
10.5.1
1
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.5.1
1
n8nio/n8n:2.41.3fdce8f852ac7
ip-address@10.3.1
10.5.1
1
neoskop/ixy:2.2.015a480e34778
ip-address@10.2.0
10.5.1
1
nocodb/nocodb:0.258.06779a4ddedf2
ip-address@9.0.5
10.5.1
1
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.