StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
488
of 17,787 indexed, latest versions
Container images
507
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 488 of 17,787 indexed charts deploy, on 507 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1507
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

488 by stars
ChartLatestAffected imagesRadar Score
redisinsightredisinsight-helmVerified publisher0.1.11 of 1See more

redisinsight redisinsight-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redisinsight:2.46699d341bd329
ip-address@9.0.5
10.3.1

Open the chart page →

1,884
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
ip-address@9.0.5
10.3.1

Open the chart page →

5,928
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
ip-address@9.0.5
10.3.1

Open the chart page →

6,794
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
ip-address@9.0.5
10.3.1

Open the chart page →

4,546
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
ip-address@10.1.0
10.3.1

Open the chart page →

3,837
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.3.1

Open the chart page →

277
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
ip-address@9.0.5
10.3.1

Open the chart page →

15,623
networking-toolboxrm3lVerified publisher0.1.01 of 1See more

networking-toolbox rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.3.1

Open the chart page →

823
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.3.1

Open the chart page →

8,798
wg-easyrm3lVerified publisher0.2.01 of 1See more

wg-easy rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
ip-address@9.0.5
10.3.1

Open the chart page →

1,158
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
ip-address@10.0.1
10.3.1

Open the chart page →

66,542
routr-connectroutr0.4.31 of 10See more

routr-connect routr 0.4.3

1 of the 10 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
ip-address@9.0.5
10.3.1

Open the chart page →

11,021
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
ip-address@9.0.5
10.3.1

Open the chart page →

5,338
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
ip-address@9.0.5
10.3.1

Open the chart page →

4,537
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.3.1

Open the chart page →

7,429
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.3.1

Open the chart page →

29,870
your-spotifyrubxkubeVerified publisher1.0.12 of 3See more

your-spotify rubxkube 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
yooooomi/your_spotify_client:1.20.0e4da90a0634c
ip-address@10.1.0
10.3.1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
ip-address@10.1.0
10.3.1

Open the chart page →

4,966
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.3.1

Open the chart page →

3,673
rybbitrybbit-helm1.3.02 of 7See more

rybbit rybbit-helm 1.3.0

2 of the 7 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.3.1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.3.1

Open the chart page →

5,833
s3-browsers3-browser0.4.11 of 1See more

s3-browser s3-browser 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
ip-address@10.1.0
10.3.1

Open the chart page →

576
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ip-address@9.0.5
10.3.1

Open the chart page →

17,736
samplesample0.1.01 of 2See more

sample sample 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.3.1

Open the chart page →

2,348
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
ip-address@10.0.1
10.3.1

Open the chart page →

4,559
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.3.1

Open the chart page →

388
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
ip-address@10.1.0
10.3.1

Open the chart page →

2,134
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.3.1

Open the chart page →

5,499
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.3.1

Open the chart page →

1,991
shopsyncshopsyncVerified publisher1.0.01 of 1See more

shopsync shopsync 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
shyamkrishna21/shopsync:latest3998b83def53
ip-address@9.0.5
10.3.1

Open the chart page →

1,088
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.02 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.3.1
mcpuse/inspector:latest91b25e3eb604
ip-address@10.1.0
10.3.1

Open the chart page →

5,230
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.3.1

Open the chart page →

2,610
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
ip-address@10.0.1
10.3.1

Open the chart page →

4,857
simple-node-expresssimple-node-express1.0.01 of 1See more

simple-node-express simple-node-express 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
devravinder/node-express-app:1.0.05325a96967b5
ip-address@9.0.5
10.3.1

Open the chart page →

752
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
ip-address@9.0.5
10.3.1

Open the chart page →

2,954
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ip-address@6.1.0
10.3.1

Open the chart page →

29,244
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ip-address@6.1.0
10.3.1

Open the chart page →

29,244
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
ip-address@10.1.0
10.3.1

Open the chart page →

590
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
ip-address@9.0.5
10.3.1

Open the chart page →

5,636
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e12 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
ip-address@9.0.5
10.3.1

Open the chart page →

15,684
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
ip-address@9.0.5
10.3.1

Open the chart page →

16,431
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091142 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
ip-address@9.0.5
10.3.1

Open the chart page →

16,431
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4692 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d4694bd113093583
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
ip-address@9.0.5
10.3.1

Open the chart page →

14,245
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3412 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.12-branch.testing3.88744-f55b3414bd113093583
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
ip-address@9.0.5
10.3.1

Open the chart page →

14,245
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b22 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
ip-address@9.0.5
10.3.1

Open the chart page →

16,050
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef2 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
ip-address@9.0.5
10.3.1

Open the chart page →

14,500
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e2 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
ip-address@9.0.5
10.3.1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ip-address@9.0.5
10.3.1

Open the chart page →

10,647
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
ip-address@9.0.5
10.3.1

Open the chart page →

3,968
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.3.1

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.3.1

Open the chart page →

920
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
ip-address@10.1.0
10.3.1

Open the chart page →

676

Container images carrying it

507 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.