StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
wachdwachdVerified publisher0.4.371 of 1See more

wachd wachd 0.4.37

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/wachd/wachd:0.4.1805b05c56da94
ip-address@10.1.0
10.5.1

Open the chart page →

1,246
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@5.9.4
10.5.1

Open the chart page →

4,020
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.5.1

Open the chart page →

9,566
discord-botxxczakiVerified publisher0.32.51 of 2See more

discord-bot xxczaki 0.32.5

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
xxczaki/discord-bot:3bf18776db30d6f5e1d8fc9ece62f13c913548aa695cbc36b5fa
ip-address@10.2.0
10.5.1

Open the chart page →

543
qleverzazukoVerified publisher0.7.11 of 2See more

qlever zazuko 0.7.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
ip-address@9.0.5
10.5.1

Open the chart page →

2,653
crowdsec-web-uizekker6Verified publisher0.52.01 of 1See more

crowdsec-web-ui zekker6 0.52.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.9.162614fd45986
ip-address@10.1.1
10.5.1

Open the chart page →

1,158
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
ip-address@10.0.1
10.5.1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
ip-address@9.0.5
10.5.1

Open the chart page →

3,771
activepiecesadnoctemVerified publisher0.6.01 of 1See more

activepieces adnoctem 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
activepieces/activepieces:0.91.058414dfc94c4
ip-address@10.1.0
10.5.1

Open the chart page →

1,158
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.5.1

Open the chart page →

1,409
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
ip-address@10.1.0
10.5.1

Open the chart page →

4,187
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.5.1

Open the chart page →

1,432
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.1.0
10.5.1

Open the chart page →

31,952
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest8aa1c158d885
ip-address@10.2.0
10.5.1

Open the chart page →

587
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
ip-address@10.1.0
10.5.1

Open the chart page →

6,930
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.5.1

Open the chart page →

5,078
homepagealareira1.0.11 of 1See more

homepage alareira 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:latest643bd0be730d
ip-address@10.5.0
10.5.1

Open the chart page →

395
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
ip-address@10.5.0
10.5.1

Open the chart page →

2,338
cross-seedalekcVerified publisher7.19.01 of 1See more

cross-seed alekc 7.19.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.5.1

Open the chart page →

1,417
excalidashalekcVerified publisher1.4.01 of 2See more

excalidash alekc 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@10.5.0
10.5.1

Open the chart page →

990
jellyseerralexmorbo-jellyseerrVerified publisher1.0.31 of 1See more

jellyseerr alexmorbo-jellyseerr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:2.2.3a324fa4d81cc
ip-address@9.0.5
10.5.1

Open the chart page →

3,448
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.5.1

Open the chart page →

5,810
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.5.0c27cafe398c2
ip-address@10.1.0
10.5.1

Open the chart page →

598
argonix-apiargonix0.5.31 of 4See more

argonix-api argonix 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:0.5.343c765355830
ip-address@9.0.5
10.5.1

Open the chart page →

5,128
assemblylineassemblylineVerified publisher7.4.211 of 12See more

assemblyline assemblyline 7.4.21

1 of the 12 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
cccs/assemblyline-ui-frontend:4.7.4.stable21c00e72d90666
ip-address@10.1.0
10.5.1

Open the chart page →

12,805
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.5.1

Open the chart page →

33,810
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
wettyoss/wetty:latest4f7c56d5b961
ip-address@9.0.5
10.5.1

Open the chart page →

6,699
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.5.1

Open the chart page →

1,818
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
fosrl/pangolin:latest00cfb631097a
ip-address@10.2.0
10.5.1

Open the chart page →

1,981
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.5.1

Open the chart page →

2,240
immichbear0.1.11 of 2See more

immich bear 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.5.1

Open the chart page →

7,356
bluerange-mosquittobluerangeOfficialVerified publisher1.1.01 of 1See more

bluerange-mosquitto bluerange 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:2690a4e5b92cc6
ip-address@10.4.0
10.5.1

Open the chart page →

137
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.5.1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.5.1

Open the chart page →

29,075
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.5.1

Open the chart page →

1,503
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.5.1

Open the chart page →

79,572
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.5.1

Open the chart page →

1,180
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.5.1

Open the chart page →

1,369
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.5.1

Open the chart page →

1,399
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.5.1

Open the chart page →

1,399
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.5.1

Open the chart page →

7,968
ghostchart-ghost0.1.61 of 2See more

ghost chart-ghost 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/ghost:6.65.0-alpine3.23fea3264f902e
ip-address@10.1.0
10.5.1

Open the chart page →

1,105
audiobookshelfcharts-derwitt-devVerified publisher1.1.11 of 1See more

audiobookshelf charts-derwitt-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
advplyr/audiobookshelf:2.36.13528a93b6442
ip-address@9.0.5
10.5.1

Open the chart page →

1,749
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ip-address@9.0.5
10.5.1

Open the chart page →

2,135
audiobookshelfchristianhuthVerified publisher2.4.11 of 1See more

audiobookshelf christianhuth 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
advplyr/audiobookshelf:2.36.13528a93b6442
ip-address@9.0.5
10.5.1

Open the chart page →

1,749
countlychristianhuthVerified publisher5.3.12 of 3See more

countly christianhuth 5.3.1

2 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
ip-address@5.9.4
10.5.1
countly/frontend:25.05.42acbc11499b6
ip-address@5.9.4
10.5.1

Open the chart page →

7,881
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ip-address@10.1.0
10.5.1

Open the chart page →

2,130
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.5.1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.5.1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.5.1

Open the chart page →

19,137
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.5.1

Open the chart page →

2,257
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.5.1

Open the chart page →

477
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
ip-address@9.0.5
10.5.1

Open the chart page →

3,922
codiac-cluster-agent-chartcodiac-cluster-agent1.0.381 of 1See more

codiac-cluster-agent-chart codiac-cluster-agent 1.0.38

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
ip-address@10.1.0
10.5.1

Open the chart page →

1,606

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.3.1
10.5.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.5.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.5.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.5.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.5.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.5.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.5.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.5.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.5.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.5.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.5.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.5.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.5.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.5.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.5.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.5.1
1
opencloudeu/yjs:1.0.02beddf0cc6db
ip-address@10.2.0
10.5.1
1
opencti/platform:7.260921.0fb396c30dc68
ip-address@10.1.0
10.5.1
1
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.5.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.5.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.5.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.5.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.5.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.5.1
1
otwld/velero-ui:0.10.31c228d9ef71b
ip-address@10.1.0
10.5.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.5.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.4.0
10.5.1
1
penpotapp/exporter:2.2.15c835ffd87ab
ip-address@9.0.5
10.5.1
1
penpotapp/exporter:2.18.0beb2c2bd9660
ip-address@10.3.1
10.5.1
1
penpotapp/mcp:2.18.09270da9fab95
ip-address@10.5.0
10.5.1
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
ip-address@10.0.1
10.5.1
1
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.5.1
1
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.5.1
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
ip-address@10.0.1
10.5.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
ip-address@9.0.5
10.5.1
1
qxip/qryn:3.2.3977acc9c7a9fd
ip-address@9.0.5
10.5.1
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.5.1
1
redis/redisinsight:2.68019fcf774631
ip-address@9.0.5
10.5.1
1
redis/redisinsight:3.2.055542a762210
ip-address@9.0.5
10.5.1
1
redis/redisinsight:2.46699d341bd329
ip-address@9.0.5
10.5.1
1
redis/redisinsight:3.485562d67a912
ip-address@9.0.5
10.5.1
1
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.5.1
1
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
ip-address@10.1.0
10.5.1
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.5.1
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.1.0
10.5.1
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.1.0
10.5.1
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.1.0
10.5.1
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.