StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.1.0
10.5.1
1
twentycrm/twenty:latest:v2.41.047bcefe4e497
ip-address@10.4.0
10.5.1
1
twentycrm/twenty:v2.43.0b2b662b1bef1
ip-address@10.4.0
10.5.1
1
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.5.1
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.5.1
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
ip-address@10.1.0
10.5.1
1
unleashorg/unleash-proxy:v1.4.82538f89e2685
ip-address@9.0.5
10.5.1
1
unleashorg/unleash-server:7.5.09adb37e399ba
ip-address@10.0.1
10.5.1
1
vabene1111/recipes:2.3.50f8d061895e9
ip-address@9.0.5
10.5.1
1
vcnngr/pnbackend:latesteaf44ad0ad1f
ip-address@9.0.5
10.5.1
1
veecode/devportal7a3d61de5e5e
ip-address@10.2.0
10.5.1
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
ip-address@9.0.5
10.5.1
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
ip-address@9.0.5
10.5.1
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
ip-address@9.0.5
10.5.1
1
wazuh/wazuh-dashboard:4.4.11787550d2358
ip-address@6.4.0
10.5.1
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.5.1
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
ip-address@9.0.5
10.5.1
1
wettyoss/wetty:latest4f7c56d5b961
ip-address@9.0.5
10.5.1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1
1
wsjbr/duplistatus:1.5.0bede86cf183f
ip-address@10.2.0
10.5.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
ip-address@9.0.5
10.5.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
ip-address@9.0.5
10.5.1
1
xxczaki/discord-bot:3bf18776db30d6f5e1d8fc9ece62f13c913548aa695cbc36b5fa
ip-address@10.2.0
10.5.1
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ip-address@9.0.5
10.5.1
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
ip-address@10.1.0
10.5.1
1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
ip-address@10.1.0
10.5.1
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
ip-address@10.1.0
10.5.1
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
ip-address@10.1.0
10.5.1
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
ip-address@9.0.5
10.5.1
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
ip-address@9.0.5
10.5.1
1
zimengxiong/excalidash-backend:0.4.271273af713c91
ip-address@9.0.5
10.5.1
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@10.5.0
10.5.1
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
ip-address@9.0.5
10.5.1
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
ip-address@9.0.5
10.5.1
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.5.1
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.5.1
1
ghcr.io/akash-network/console-api:2.64.0ba359097329d
ip-address@9.0.5
10.5.1
1
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
ip-address@9.0.5
10.5.1
1
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
ip-address@9.0.5
10.5.1
1
ghcr.io/akash-network/provider-console-security:1.0.0b87a48ec51dd
ip-address@9.0.5
10.5.1
1
ghcr.io/akash-network/provider-proxy:1.4.353f533d7c6f8
ip-address@9.0.5
10.5.1
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.5.1
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
ip-address@9.0.5
10.5.1
1
ghcr.io/appscode/platform-ui:2.5.0c27cafe398c2
ip-address@10.1.0
10.5.1
1
ghcr.io/argonix-io/argonix-api-frontend:0.5.343c765355830
ip-address@9.0.5
10.5.1
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ip-address@10.1.0
10.5.1
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
ip-address@9.0.5
10.5.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.5.1
1
ghcr.io/automation64/toolbox/oraclelinux-9-toolbox:latest7af2216c7b9e
ip-address@10.2.0
10.5.1
1
ghcr.io/backstage/backstage:lateste2a48bb6ab55
ip-address@10.2.0
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.