StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.5.1

Open the chart page →

11,114
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
ip-address@9.0.5
10.5.1

Open the chart page →

2,981
libredb-studiolibredb-studioVerified publisher0.1.721 of 1See more

libredb-studio libredb-studio 0.1.72

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.17.0ce4d58724e25
ip-address@10.5.0
10.5.1

Open the chart page →

989
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
ip-address@9.0.5
10.5.1

Open the chart page →

8,497
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
ip-address@10.2.0
10.5.1

Open the chart page →

775
ghostcloudpirates-ghostVerified publisher0.20.261 of 3See more

ghost cloudpirates-ghost 0.20.26

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/ghost:6.64.0586821cfebac
ip-address@10.1.0
10.5.1

Open the chart page →

7,399
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
ip-address@9.0.5
10.5.1

Open the chart page →

7,710
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
ip-address@9.0.5
10.5.1

Open the chart page →

1,378
convertigoconvertigoOfficialVerified publisher8.4.41 of 5See more

convertigo convertigo 8.4.4

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
ip-address@9.0.5
10.5.1

Open the chart page →

15,734
cosmocosmo-platformOfficialVerified publisher0.20.03 of 10See more

cosmo cosmo-platform 0.20.0

3 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
ip-address@9.0.5
10.5.1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
ip-address@9.0.5
10.5.1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
ip-address@9.0.5
10.5.1

Open the chart page →

30,770
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.5.1

Open the chart page →

3,583
duplistatusduplistatusVerified publisher1.3.01 of 2See more

duplistatus duplistatus 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.5.0bede86cf183f
ip-address@10.2.0
10.5.1

Open the chart page →

887
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
diygod/rsshub:latest22845ada2f14
ip-address@10.2.0
10.5.1

Open the chart page →

1,493
hermes-agenthermes-agentVerified publisher1.16.01 of 1See more

hermes-agent hermes-agent 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.5.1

Open the chart page →

5,766
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.5.1

Open the chart page →

32,182
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
aaronshaf/dynamodb-admin:latestac41724cd997
ip-address@10.1.0
10.5.1

Open the chart page →

1,355
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
shieldsio/shields:nextf0fccbce3b75
ip-address@10.2.0
10.5.1

Open the chart page →

1,586
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
ip-address@9.0.5
10.5.1

Open the chart page →

2,983
pacmanpacmanVerified publisher2.0.21 of 2See more

pacman pacman 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/shuguet/pacman:latesta0ec71732c3c
ip-address@10.1.0
10.5.1

Open the chart page →

676
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
ip-address@9.0.5
10.5.1

Open the chart page →

2,833
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1

Open the chart page →

1,077
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.5.1

Open the chart page →

10,657
feedbacksystemthm-mni-iiVerified publisher0.48.03 of 14See more

feedbacksystem thm-mni-ii 0.48.0

3 of the 14 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/thm-mni-ii/fbs-collab:v2.0.1366bc4ec1079
ip-address@10.1.0
10.5.1
ghcr.io/thm-mni-ii/fbs-qcm-backend:v2.0.12633b7c61fb1
ip-address@9.0.5
10.5.1
ghcr.io/thm-mni-ii/fbs-qcm-frontend:v2.0.128c98d86ed77
ip-address@9.0.5
10.5.1

Open the chart page →

25,559
wgerwgerOfficialVerified publisher2.0.01 of 7See more

wger wger 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latest413a0c813e96
ip-address@10.2.0
10.5.1

Open the chart page →

7,565
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.5.1

Open the chart page →

4,399
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.5.1

Open the chart page →

1,161
agentareaagentareaVerified publisher0.0.202 of 16See more

agentarea agentarea 0.0.20

2 of the 16 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
agentarea/agentarea-frontend:latest58e492779455
ip-address@10.1.0
10.5.1
agentarea/agentarea-mcp-runner:latest615da5917632
ip-address@10.1.0
10.5.1

Open the chart page →

13,488
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.5.1

Open the chart page →

6,488
dbgateappscodeVerified publisher2026.3.301 of 1See more

dbgate appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.0-alpine287077002446
ip-address@9.0.5
10.5.1

Open the chart page →

640
kinesisaws-kinesis-local0.8.01 of 1See more

kinesis aws-kinesis-local 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.5.1

Open the chart page →

411
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.5.1

Open the chart page →

2,143
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.5.1

Open the chart page →

1,915
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.5.1

Open the chart page →

2,578
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.5.1

Open the chart page →

156
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.5.1

Open the chart page →

1,380
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.5.1

Open the chart page →

1,988
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/data-fair/notify:3c739b74dabb0
ip-address@9.0.5
10.5.1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.5.1

Open the chart page →

39,657
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.5.1

Open the chart page →

9,782
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.5.1

Open the chart page →

8,071
jellystatdjjudas21Verified publisher1.0.11 of 1See more

jellystat djjudas21 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.12e61c759ec706
ip-address@10.2.0
10.5.1

Open the chart page →

1,756
joplin-serverdjjudas21Verified publisher6.0.01 of 1See more

joplin-server djjudas21 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
joplin/server:3.7.23f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

2,721
domain-lockerdomain-locker0.3.11 of 2See more

domain-locker domain-locker 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
lissy93/domain-locker:latest58a903b2cdd9
ip-address@10.2.0
10.5.1

Open the chart page →

700
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
ip-address@9.0.5
10.5.1

Open the chart page →

75,634
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-101913.

Open the chart page →

33,121
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
ip-address@9.0.5
10.5.1

Open the chart page →

1,658
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ip-address@9.0.5
10.5.1

Open the chart page →

11,928
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.5.1

Open the chart page →

3,360
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
globalping/globalping-probe:latestb8469caf783a
ip-address@10.1.0
10.5.1

Open the chart page →

547
ghostgroundhog2k0.212.141 of 1See more

ghost groundhog2k 0.212.14

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
ip-address@10.1.0
10.5.1

Open the chart page →

2,115
growthbookgrowthbook5.1.01 of 2See more

growthbook growthbook 5.1.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
growthbook/growthbook:5.1.0c8a124f55dca
ip-address@10.5.0
10.5.1

Open the chart page →

447

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.5.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.5.1
1
library/ghost:6.64.0586821cfebac
ip-address@10.1.0
10.5.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.5.1
1
library/ghost:6.65.0-alpine3.23fea3264f902e
ip-address@10.1.0
10.5.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.5.1
1
library/node:22-bookworm-slim48e4b67d85f8
ip-address@10.1.0
10.5.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.5.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.5.1
1
library/node:latestfa271c47a5d8
ip-address@10.5.0
10.5.1
1
lissy93/domain-locker:latest58a903b2cdd9
ip-address@10.2.0
10.5.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.5.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.5.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.5.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.5.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.5.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.5.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.5.1
1
louislam/uptime-kuma:170233f4acb51
ip-address@10.0.1
10.5.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.5.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.5.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.5.1
1
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.5.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.5.1
1
luligu/matterbridge:3.10.11e278cf685f91
ip-address@10.2.0
10.5.1
1
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.5.1
1
mauricenino/dashdot:5.9.2236997816917
ip-address@9.0.5
10.5.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.5.1
1
mcp/kubernetes:latest5ffbf7f0a8aa
ip-address@10.2.0
10.5.1
1
mcpuse/inspector:latest4f23f55e7c96
ip-address@10.1.0
10.5.1
1
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.5.1
1
mishtinetwork/operator:latestbb3fe67a5f7c
ip-address@9.0.5
10.5.1
1
misskey/misskey:12.110.1e08b7c478093
ip-address@7.1.0
10.5.1
1
mitre/heimdall2:release-latest06f6e72d416a
ip-address@10.4.0
10.5.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.5.1
1
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.5.1
1
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.5.1
1
moreillon/food-manager:lateste8fd856e593d
ip-address@9.0.5
10.5.1
1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.5.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.5.1
1
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.5.1
1
n8nio/n8n:2.40.59f693fd55655
ip-address@10.3.1
10.5.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.3.1
10.5.1
1
n8nio/n8n:1.33.1dd171d45102a
ip-address@9.0.5
10.5.1
1
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.5.1
1
n8nio/n8n:2.41.3fdce8f852ac7
ip-address@10.3.1
10.5.1
1
neoskop/ixy:2.2.015a480e34778
ip-address@10.2.0
10.5.1
1
nocodb/nocodb:0.258.06779a4ddedf2
ip-address@9.0.5
10.5.1
1
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.