StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.5.1
1
sharanalwar/redchef-frontend:latest5e82950b16b7
ip-address@9.0.5
10.5.1
1
shieldsio/shields:nextf0fccbce3b75
ip-address@10.2.0
10.5.1
1
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.5.1
1
shyamkrishna21/shopsync:latest3998b83def53
ip-address@9.0.5
10.5.1
1
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.5.1
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
ip-address@9.0.5
10.5.1
1
skylenet/ethstats-server:pow-latestd757cc016198
ip-address@5.9.4
10.5.1
1
sondresjo/altinnendata-app:v1.9.68bc03653f87e
ip-address@10.5.0
10.5.1
1
sondresjo/garge-app:v1.22.0c4b8f096df6b
ip-address@10.5.0
10.5.1
1
sondresjo/nstuning-app:v1.6.15b7cc8f543551
ip-address@10.5.0
10.5.1
1
sondresjo/pyttogpanne-app:v1.0.3706b0218f7b4
ip-address@10.5.0
10.5.1
1
sondresjo/sjolystinnovation-app:v1.3.04ce832347953
ip-address@10.5.0
10.5.1
1
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.26.3092384dba45d
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
ip-address@9.0.5
10.5.1
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.26.379f14a2bf931
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
ip-address@9.0.5
10.5.1
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
ip-address@9.0.5
10.5.1
1
stnsmith/fossflow:lateste448ab346cb3
ip-address@10.5.0
10.5.1
1
supabase/postgres-meta:v0.96.6a84cc713585e
ip-address@9.0.5
10.5.1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
ip-address@9.0.5
10.5.1
1
supabase/storage-api:latest5fea789899d4
ip-address@10.2.0
10.5.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.1.0
10.5.1
1
supabase/storage-api:v1.12.0f983fb50bd95
ip-address@9.0.5
10.5.1
1
supabase/studio:20241021-9f9b08326d8070c55e9
ip-address@9.0.5
10.5.1
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
ip-address@10.1.0
10.5.1
1
supabase/studio:latestfdb56cfa1705
ip-address@10.1.0
10.5.1
1
supporttools/uptime-kuma:v2.6f8a49ed65809
ip-address@9.0.5
10.5.1
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
ip-address@10.5.0
10.5.1
1
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.5.1
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.5.1
1
tensorzero/ui:2026.6.0f2563d54724e
ip-address@10.0.1
10.5.1
1
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.5.1
1
th0th/node-red:4.0.3-debiand06fa39f7406
ip-address@9.0.5
10.5.1
1
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.5.1
1
trackerforce/switcher-api:latest28ee0c4e0b88
ip-address@10.2.0
10.5.1
1
trackerforce/switcher-resolver-node:latest67e2c261f7b4
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.