StackRadar

CVE-2026-101913

Medium

Advisory

Published 28 Sept 2026In the index since 29 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
557
of 17,939 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts

Carried by container images the latest versions of 557 of 17,939 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+9 more10.5.1568
OSV records
GHSA-rpw4-54j3-4h4q
Trending
Rank 14 in indexed charts, since 29 Sept 2026. See the ranking →

Charts affected

557 by stars
ChartLatestAffected imagesRadar Score
apisix-ingress-controllerwenerme1.4.01 of 2See more

apisix-ingress-controller wenerme 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1

Open the chart page →

1,844
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1

Open the chart page →

328
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1

Open the chart page →

238
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
ip-address@10.2.0
10.5.1

Open the chart page →

3,698
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.5.1

Open the chart page →

6,636
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.5.1

Open the chart page →

14,832
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-101913.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.5.1

Open the chart page →

9,718

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latest6a8f32aa11bc
ip-address@10.5.0
10.5.1
4
redis/redisinsight:3.8:latestb5e19ee240ab
ip-address@9.0.5
10.5.1
4
joplin/server:3.7.2:latest3f7b852959aa
ip-address@10.2.0
10.5.1
3
library/node:lts64af3819f927
ip-address@10.2.0
10.5.1
3
library/node:24.21.0-alpine:lts-alpineebfe2f904627
ip-address@10.2.0
10.5.1
3
localstack/localstack:latest4abc29e923e5
ip-address@10.5.0
10.5.1
3
opensearchproject/opensearch-dashboards:3.8.07fb7ec1b33f1
ip-address@10.2.0
10.5.1
3
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.5.1
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.5.1
3
ghcr.io/homarr-labs/homarr:v1.77.2f0fb462299af
ip-address@10.2.0
10.5.1
3
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
ip-address@10.1.0
10.5.1
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ip-address@10.0.1
10.5.1
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.5.0
10.5.1
3
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.5.1
2
advplyr/audiobookshelf:2.36.13528a93b6442
ip-address@9.0.5
10.5.1
2
epamedp/krci-portal:0.8.0687acf641097
ip-address@9.0.5
10.5.1
2
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.5.1
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.5.1
2
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.5.1
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.5.1
2
langflowai/langflow:latest79c02794adeb
ip-address@10.3.1
10.5.1
2
library/ghost:6.65.090592b712b6b
ip-address@10.1.0
10.5.1
2
library/mongo-express:1.0.2:latest1b23d7976f02
ip-address@9.0.5
10.5.1
2
library/node:24.21.0-alpine3.239ec4a2e28987
ip-address@10.2.0
10.5.1
2
louislam/uptime-kuma:2.5.4917318f9d7be
ip-address@10.1.0
10.5.1
2
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.5.1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.1.0
10.5.1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.5.1
2
louislam/uptime-kuma:2.5.5c74379ac4509
ip-address@10.1.0
10.5.1
2
mojaloop/reporting:v12.1.0d480a62103d6
ip-address@9.0.5
10.5.1
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
ip-address@9.0.5
10.5.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
ip-address@9.0.5
10.5.1
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
ip-address@9.0.5
10.5.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
ip-address@9.0.5
10.5.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ip-address@10.0.1
10.5.1
2
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.5.1
2
nodered/node-red:5.0.7:latesta649dd711d55
ip-address@10.2.0
10.5.1
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
ip-address@10.2.0
10.5.1
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
ip-address@6.4.0
10.5.1
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.5.1
2
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.5.1
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.5.1
2
requarks/wiki:2:latest68f0d1848261
ip-address@5.9.4
10.5.1
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.5.1
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
ip-address@9.0.5
10.5.1
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
ip-address@9.0.5
10.5.1
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ip-address@6.1.0
10.5.1
2
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.5.1
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
ip-address@10.5.0
10.5.1
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.5.1
2

syft 1.42.1 · advisories as of 29 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.