StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
ip-address@9.0.5
10.5.1
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
ip-address@9.0.5
10.5.1
1
ghcr.io/bluesky-social/pds:0.405e164855fa1
ip-address@10.2.0
10.5.1
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.5.1
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ip-address@9.0.5
10.5.1
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
ip-address@10.5.0
10.5.1
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.5.1
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.5.1
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.5.1
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
ip-address@9.0.5
10.5.1
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
ip-address@9.0.5
10.5.1
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.5.1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ip-address@9.0.5
10.5.1
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.5.1
1
ghcr.io/cameri/nostream:mainc134ac2fa289
ip-address@10.1.0
10.5.1
1
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.5.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.5.1
1
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.5.1
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.5.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ip-address@9.0.5
10.5.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
ip-address@9.0.5
10.5.1
1
ghcr.io/data-fair/notify:3c739b74dabb0
ip-address@9.0.5
10.5.1
1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.5.1
1
ghcr.io/devops-dojo7/fauxgpu/web:0.2.4691dd15d6bca
ip-address@10.1.0
10.5.1
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.5.1
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.5.1
1
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.5.1
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.5.1
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
ip-address@9.0.5
10.5.1
1
ghcr.io/firecrawl/firecrawl:2.11.408966ef7f9a385
ip-address@10.1.0
10.5.1
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
ip-address@9.0.5
10.5.1
1
ghcr.io/flanksource/facet:0.1.73a0323f4283e5
ip-address@10.1.0
10.5.1
1
ghcr.io/fluxerapp/fluxer-api:2026.820.164808f683541d5374
ip-address@10.2.0
10.5.1
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.5.1
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.5.1
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.5.1
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.5.1
1
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.5.1
1
ghcr.io/gethomepage/homepage:v1.11.0b129cb0f674b
ip-address@9.0.5
10.5.1
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
ip-address@10.1.0
10.5.1
1
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
ip-address@9.0.5
10.5.1
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
ip-address@10.1.0
10.5.1
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.5.1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.5.1
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.5.1
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.5.1
1
ghcr.io/immich-app/immich-server:v3.2.279cc1623323d
ip-address@10.2.0
10.5.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ip-address@9.0.5
10.5.1
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
ip-address@9.0.5
10.5.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
ip-address@9.0.5
10.5.1
1

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.