StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b22 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

2 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
ip-address@9.0.5
10.5.1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
ip-address@9.0.5
10.5.1

Open the chart page →

16,944
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef2 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

2 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
ip-address@9.0.5
10.5.1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
ip-address@9.0.5
10.5.1

Open the chart page →

16,558
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e2 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

2 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
ip-address@9.0.5
10.5.1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ip-address@9.0.5
10.5.1

Open the chart page →

11,853
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
ip-address@9.0.5
10.5.1

Open the chart page →

4,285
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1

Open the chart page →

6,186
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1

Open the chart page →

999
strapistrapi-xmv0.1.21 of 1See more

strapi strapi-xmv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
ip-address@10.1.0
10.5.1

Open the chart page →

778
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.5.1

Open the chart page →

1,861
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
ip-address@9.0.5
10.5.1

Open the chart page →

4,345
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
ip-address@9.0.5
10.5.1

Open the chart page →

5,042
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.5.1

Open the chart page →

4,141
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
ip-address@10.0.1
10.5.1

Open the chart page →

4,348
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
supabase/storage-api:latest5fea789899d4
ip-address@10.2.0
10.5.1
supabase/studio:latestfdb56cfa1705
ip-address@10.1.0
10.5.1

Open the chart page →

9,174
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
ip-address@9.0.5
10.5.1

Open the chart page →

12,369
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.5.1

Open the chart page →

41,621
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.5.1

Open the chart page →

5,986
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
ip-address@9.0.5
10.5.1

Open the chart page →

2,506
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.5.1

Open the chart page →

4,773
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.5.1

Open the chart page →

3,640
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.5.1

Open the chart page →

5,991
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
ip-address@9.0.5
10.5.1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
ip-address@9.0.5
10.5.1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
ip-address@9.0.5
10.5.1

Open the chart page →

7,610
altinnendata-apptumogroup0.1.221 of 1See more

altinnendata-app tumogroup 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.68bc03653f87e
ip-address@10.5.0
10.5.1

Open the chart page →

646
nstuning-apptumogroup0.1.221 of 1See more

nstuning-app tumogroup 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.15b7cc8f543551
ip-address@10.5.0
10.5.1

Open the chart page →

646
pyttogpanne-apptumogroup0.1.41 of 1See more

pyttogpanne-app tumogroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sondresjo/pyttogpanne-app:v1.0.3706b0218f7b4
ip-address@10.5.0
10.5.1

Open the chart page →

646
sjolystinnovation-apptumogroup0.1.51 of 1See more

sjolystinnovation-app tumogroup 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sondresjo/sjolystinnovation-app:v1.3.04ce832347953
ip-address@10.5.0
10.5.1

Open the chart page →

646
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.5.1

Open the chart page →

5,790
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
ip-address@9.0.5
10.5.1

Open the chart page →

936
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.5.1

Open the chart page →

404
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
ip-address@10.1.0
10.5.1

Open the chart page →

2,245
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
ip-address@9.0.5
10.5.1

Open the chart page →

984
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
ip-address@9.0.5
10.5.1

Open the chart page →

2,737
fossflowunxwaresVerified publisher2026.2.11 of 1See more

fossflow unxwares 2026.2.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
stnsmith/fossflow:lateste448ab346cb3
ip-address@10.5.0
10.5.1

Open the chart page →

191
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.5.1

Open the chart page →

5,486
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.5.1

Open the chart page →

3,942
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
ip-address@9.0.5
10.5.1

Open the chart page →

5,114
devportalveecode-platform-nextVerified publisher0.1.251 of 1See more

devportal veecode-platform-next 0.1.25

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned7a3d61de5e5e
ip-address@10.2.0
10.5.1

Open the chart page →

2,015
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.5.1

Open the chart page →

4,671
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.5.1

Open the chart page →

2,408
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.5.1

Open the chart page →

6,844
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
ip-address@10.4.0
10.5.1

Open the chart page →

74,473
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.5.1

Open the chart page →

1,957
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.5.1

Open the chart page →

3,096
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_result6e92e5a231fa
ip-address@9.0.5
10.5.1

Open the chart page →

7,337
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.5.1

Open the chart page →

6,107
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.5.1

Open the chart page →

5,853
welcome-clientwelcome-client26.0.01 of 1See more

welcome-client welcome-client 26.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
lucassandin/welcome-client:latest48468b1ccd16
ip-address@9.0.5
10.5.1

Open the chart page →

1,553
apisix-ingress-controllerwener1.4.01 of 2See more

apisix-ingress-controller wener 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswener3.8.01 of 1See more

opensearch-dashboards wener 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowener4.35.11 of 1See more

verdaccio wener 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.5.1

Open the chart page →

4,020

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.5.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.5.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.5.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.5.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.5.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.5.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.5.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.5.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.5.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.5.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.5.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.5.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.5.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.5.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.5.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.5.1
1
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.5.1
1
opencti/platform:7.260921.0fb396c30dc68
ip-address@10.1.0
10.5.1
1
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.5.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.5.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.5.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.5.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.5.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.5.1
1
otwld/velero-ui:0.10.31c228d9ef71b
ip-address@10.1.0
10.5.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.5.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.5.1
1
penpotapp/exporter:2.2.15c835ffd87ab
ip-address@9.0.5
10.5.1
1
penpotapp/exporter:2.18.0beb2c2bd9660
ip-address@10.3.1
10.5.1
1
penpotapp/mcp:2.18.09270da9fab95
ip-address@10.5.0
10.5.1
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
ip-address@10.0.1
10.5.1
1
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.5.1
1
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.5.1
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
ip-address@10.0.1
10.5.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
ip-address@9.0.5
10.5.1
1
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.5.1
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.5.1
1
redis/redisinsight:2.68019fcf774631
ip-address@9.0.5
10.5.1
1
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.5.1
1
redis/redisinsight:2.46699d341bd329
ip-address@9.0.5
10.5.1
1
redis/redisinsight:3.485562d67a912
ip-address@9.0.5
10.5.1
1
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.5.1
1
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
ip-address@10.1.0
10.5.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.5.1
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.1.0
10.5.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.1.0
10.5.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.1.0
10.5.1
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.