StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.5.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.5.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.5.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.5.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.5.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.5.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.5.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.5.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.5.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.5.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.5.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.5.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.5.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.5.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.5.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.5.1
1
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.5.1
1
opencti/platform:7.260921.0fb396c30dc68
ip-address@10.1.0
10.5.1
1
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.5.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.5.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.5.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.5.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.5.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.5.1
1
otwld/velero-ui:0.10.31c228d9ef71b
ip-address@10.1.0
10.5.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.5.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.5.1
1
penpotapp/exporter:2.2.15c835ffd87ab
ip-address@9.0.5
10.5.1
1
penpotapp/exporter:2.18.0beb2c2bd9660
ip-address@10.3.1
10.5.1
1
penpotapp/mcp:2.18.09270da9fab95
ip-address@10.5.0
10.5.1
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
ip-address@10.0.1
10.5.1
1
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.5.1
1
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.5.1
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
ip-address@10.0.1
10.5.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
ip-address@9.0.5
10.5.1
1
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.5.1
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.5.1
1
redis/redisinsight:2.68019fcf774631
ip-address@9.0.5
10.5.1
1
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.5.1
1
redis/redisinsight:2.46699d341bd329
ip-address@9.0.5
10.5.1
1
redis/redisinsight:3.485562d67a912
ip-address@9.0.5
10.5.1
1
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.5.1
1
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
ip-address@10.1.0
10.5.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.5.1
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.1.0
10.5.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.1.0
10.5.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.1.0
10.5.1
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.