StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
488
of 17,787 indexed, latest versions
Container images
507
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 488 of 17,787 indexed charts deploy, on 507 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1507
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

488 by stars
ChartLatestAffected imagesRadar Score
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.3.1

Open the chart page →

1,653
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
ip-address@9.0.5
10.3.1

Open the chart page →

4,898
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.3.1

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
ip-address@10.0.1
10.3.1

Open the chart page →

3,967
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.3.1
supabase/studio:latest94a2a9d2906e
ip-address@10.1.0
10.3.1

Open the chart page →

9,469
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
ip-address@9.0.5
10.3.1

Open the chart page →

11,674
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.3.1

Open the chart page →

36,661
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.3.1

Open the chart page →

5,652
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
ip-address@9.0.5
10.3.1

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.3.1

Open the chart page →

4,662
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.3.1

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1

Open the chart page →

5,489
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
ip-address@9.0.5
10.3.1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
ip-address@9.0.5
10.3.1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
ip-address@9.0.5
10.3.1

Open the chart page →

6,940
altinnendata-apptumogroup0.1.171 of 1See more

altinnendata-app tumogroup 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.1c2707839d8a3
ip-address@9.0.5
10.3.1

Open the chart page →

1,755
nstuning-apptumogroup0.1.181 of 1See more

nstuning-app tumogroup 0.1.18

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.113a6795bf36da
ip-address@9.0.5
10.3.1

Open the chart page →

1,755
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.3.1

Open the chart page →

5,599
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.3.1

Open the chart page →

352
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
ip-address@10.1.0
10.3.1

Open the chart page →

2,029
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
ip-address@9.0.5
10.3.1

Open the chart page →

929
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
ip-address@9.0.5
10.3.1

Open the chart page →

2,622
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.3.1

Open the chart page →

5,234
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.3.1

Open the chart page →

3,747
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
ip-address@9.0.5
10.3.1

Open the chart page →

4,769
devportalveecode-platform-nextVerified publisher0.1.221 of 1See more

devportal veecode-platform-next 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
ip-address@10.2.0
10.3.1

Open the chart page →

1,806
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.3.1

Open the chart page →

4,360
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.3.1

Open the chart page →

2,077
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.3.1

Open the chart page →

6,470
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.3.1

Open the chart page →

1,931
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.3.1

Open the chart page →

3,030
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.3.1

Open the chart page →

5,774
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.3.1

Open the chart page →

5,484
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.3.1

Open the chart page →

1,634
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.3.1

Open the chart page →

280
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.3.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.3.1

Open the chart page →

5,472
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.3.1

Open the chart page →

14,172
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.3.1

Open the chart page →

9,381

Container images carrying it

507 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.3.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.3.1
1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.3.1
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
ip-address@9.0.5
10.3.1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
ip-address@9.0.5
10.3.1
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.3.1
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
ip-address@9.0.5
10.3.1
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
ip-address@10.1.0
10.3.1
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
ip-address@10.0.1
10.3.1
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
ip-address@9.0.5
10.3.1
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
ip-address@9.0.5
10.3.1
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.3.1
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.3.1
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
ip-address@10.1.1
10.3.1
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.1.0
10.3.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
ip-address@9.0.5
10.3.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
ip-address@9.0.5
10.3.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
ip-address@9.0.5
10.3.1
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
ip-address@10.1.0
10.3.1
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
ip-address@9.0.5
10.3.1
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
ip-address@10.1.0
10.3.1
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
ip-address@10.1.0
10.3.1
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
ip-address@10.0.1
10.3.1
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
ip-address@9.0.5
10.3.1
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.3.1
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
ip-address@9.0.5
10.3.1
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
ip-address@9.0.5
10.3.1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
ip-address@9.0.5
10.3.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
ip-address@9.0.5
10.3.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
ip-address@9.0.5
10.3.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
ip-address@10.1.0
10.3.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
ip-address@9.0.5
10.3.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
ip-address@9.0.5
10.3.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
ip-address@10.1.0
10.3.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
ip-address@10.1.0
10.3.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
ip-address@9.0.5
10.3.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.3.1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.3.1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
ip-address@9.0.5
10.3.1
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ip-address@6.4.0
10.3.1
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ip-address@10.1.0
10.3.1
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.3.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
ip-address@10.1.0
10.3.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
ip-address@10.1.0
10.3.1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
ip-address@9.0.5
10.3.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
ip-address@9.0.5
10.3.1
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
ip-address@9.0.5
10.3.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
ip-address@10.1.0
10.3.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
ip-address@10.1.0
10.3.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
ip-address@9.0.5
10.3.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.