StackRadar

CVE-2026-54272

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
116
deployed by those charts
Fix available
1 of 1
affected package

ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 116 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.1.1, 10.2.010.2.1116
OSV records
GHSA-22jq-vg5j-6vgg

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.2.1

Open the chart page →

8,303
homarrmedia-servarrVerified publisher0.55.11 of 1See more

homarr media-servarr 0.55.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
ip-address@10.2.0
10.2.1

Open the chart page →

435
miot-dashboard-servermicroboxlabs0.1.11 of 1See more

miot-dashboard-server microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-dashboard-server:latest19b910920ab1
ip-address@10.2.0
10.2.1

Open the chart page →

237
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.1

Open the chart page →

10,603
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.2.1

Open the chart page →

1,759
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.1

Open the chart page →

1,038
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
ip-address@10.2.0
10.2.1

Open the chart page →

595
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.2.1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.2.1

Open the chart page →

4,660
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.1

Open the chart page →

1,038
portalplatform-mesh-portal0.19.41 of 1See more

portal platform-mesh-portal 0.19.4

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
ip-address@10.2.0
10.2.1

Open the chart page →

301
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.2.1

Open the chart page →

276
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.1

Open the chart page →

9,047
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.2.1

Open the chart page →

30,219
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.2.1

Open the chart page →

3,707
rybbitrybbit-helm1.3.02 of 7See more

rybbit rybbit-helm 1.3.0

2 of the 7 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.2.1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.2.1

Open the chart page →

5,819
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.2.1

Open the chart page →

387
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.2.1

Open the chart page →

1,991
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.1

Open the chart page →

2,638
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.1

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.1

Open the chart page →

919
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.2.1

Open the chart page →

9,556
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.2.1

Open the chart page →

5,535
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.2.1

Open the chart page →

5,550
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
ip-address@10.2.0
10.2.1

Open the chart page →

1,787
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.2.1

Open the chart page →

1,961
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.2.1

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-54272.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@10.2.0
10.2.1

Open the chart page →

5,459

Container images carrying it

116 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@10.2.0
10.2.1
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.2.1
1
ghcr.io/microboxlabs/miot-dashboard-server:latest19b910920ab1
ip-address@10.2.0
10.2.1
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
ip-address@10.2.0
10.2.1
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
ip-address@10.2.0
10.2.1
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.2.1
1
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
ip-address@10.2.0
10.2.1
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.2.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.2.1
1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.2.1
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.2.1
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.2.1
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
ip-address@10.1.1
10.2.1
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.2.1
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.2.1
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
ip-address@10.2.0
10.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.