StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
487
of 17,781 indexed, latest versions
Container images
506
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 487 of 17,781 indexed charts deploy, on 506 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1506
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

487 by stars
ChartLatestAffected imagesRadar Score
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1

Open the chart page →

3,806
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1

Open the chart page →

948
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.3.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.3.1

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.1.0
10.3.1

Open the chart page →

4,018
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.3.1

Open the chart page →

7,633
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.3.1

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.3.1

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.3.1

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.3.1

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1

Open the chart page →

2,463
homarrhelmforgeVerified publisher1.2.81 of 1See more

homarr helmforge 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.3.1

Open the chart page →

435
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.3.1

Open the chart page →

11,042
matterbridgehelmforgeVerified publisher1.0.21 of 1See more

matterbridge helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1

Open the chart page →

895
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.3.1

Open the chart page →

792
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.3.1

Open the chart page →

9,653
opencuthelmforgeVerified publisher1.1.91 of 5See more

opencut helmforge 1.1.9

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.3.1

Open the chart page →

3,726
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.3.1

Open the chart page →

2,538
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.3.1

Open the chart page →

453
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.3.1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.3.1

Open the chart page →

3,025
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.3.1

Open the chart page →

6,012
twentyhelmforgeVerified publisher1.0.01 of 5See more

twenty helmforge 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.3.1

Open the chart page →

2,818
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1

Open the chart page →

30,099
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.3.1

Open the chart page →

25,017
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.3.1

Open the chart page →

1,468
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.3.1

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.3.1

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.3.1

Open the chart page →

3,407
multicaicoretechVerified publisher0.4.421 of 5See more

multica icoretech 0.4.42

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/multica-ai/multica-web:v0.4.43fc937fbbf8e5
ip-address@10.1.0
10.3.1

Open the chart page →

2,722
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.3.1

Open the chart page →

3,154
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.3.1

Open the chart page →

8,967
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.3.1

Open the chart page →

6,254
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.3.1

Open the chart page →

1,235
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.3.1

Open the chart page →

11,812
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
ip-address@9.0.5
10.3.1

Open the chart page →

3,014
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.3.1

Open the chart page →

5,826
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.3.1

Open the chart page →

424
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.3.1

Open the chart page →

2,149
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1

Open the chart page →

914
github-exporterjkroepkeVerified publisher1.4.01 of 1See more

github-exporter jkroepke 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1

Open the chart page →

1,031
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.3.1

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.03 of 8See more

shinsei-manager jtekt 0.2.0

3 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.3.1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.3.1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.3.1

Open the chart page →

63,461
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.3.1

Open the chart page →

1,966
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.3.1

Open the chart page →

2,611
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.3.1

Open the chart page →

8,811
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.3.1

Open the chart page →

2,350
floodk8s-home-lab-repo7.3.01 of 1See more

flood k8s-home-lab-repo 7.3.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.3.1

Open the chart page →

746
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1

Open the chart page →

3,092
k8s-jacoco-operatork8s-jacoco-operator0.4.02 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.3.1

Open the chart page →

2,437

Container images carrying it

506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
devravinder/node-express-app:1.0.05325a96967b5
ip-address@9.0.5
10.3.1
1
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.3.1
1
directus/directus:11.1.0e3c8bb975350
ip-address@9.0.5
10.3.1
1
diygod/rsshub:latest1d4b508b6357
ip-address@10.2.0
10.3.1
1
diygod/rsshub:2025-11-097a6312cac0d5
ip-address@10.0.1
10.3.1
1
docmost/docmost:0.95.041c8d777cf23
ip-address@10.1.0
10.3.1
1
documenso/documenso:v1.8.17f16a9449f18
ip-address@9.0.5
10.3.1
1
drumsergio/genieacs:1.2.16.028244054e1bf
ip-address@10.1.0
10.3.1
1
drumsergio/lynxprompt:2.0.75c6afb6679301
ip-address@10.1.0
10.3.1
1
drumsergio/pumperly:1.4.885bbc3915e9e
ip-address@10.1.0
10.3.1
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.1.0
10.3.1
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.3.1
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
ip-address@9.0.5
10.3.1
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
ip-address@10.2.0
10.3.1
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
ip-address@10.2.0
10.3.1
1
etherpad/etherpad:2.7.2b723fe5f2594
ip-address@10.1.0
10.3.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ip-address@9.0.5
10.3.1
1
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.3.1
1
ethpandaops/ethereumjs:masterfb84b718500f
ip-address@9.0.5
10.3.1
1
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.3.1
1
fallenbagel/jellyseerr:latest4538137bc5af
ip-address@9.0.5
10.3.1
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
ip-address@9.0.5
10.3.1
1
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.3.1
1
felipecs8/landing-page:v1db6d44e325a1
ip-address@9.0.5
10.3.1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
ip-address@9.0.5
10.3.1
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
ip-address@9.0.5
10.3.1
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
ip-address@9.0.5
10.3.1
1
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.3.1
1
folioci/mod-graphql:latestf0655a6a08fd
ip-address@9.0.5
10.3.1
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
ip-address@9.0.5
10.3.1
1
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.3.1
1
fosrl/pangolin:1.13.0c32ad797ab96
ip-address@10.0.1
10.3.1
1
fthomas/scala-steward:latest367afe974b7a
ip-address@10.1.0
10.3.1
1
gethue/hue:latest7d5c1b9f8a79
ip-address@10.1.0
10.3.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.3.1
1
globalping/globalping-probe:latest8acbd23009fd
ip-address@10.1.0
10.3.1
1
haohanyang/compass-web:0.5.054f2112602ee
ip-address@10.1.0
10.3.1
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.3.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ip-address@9.0.5
10.3.1
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.3.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ip-address@9.0.5
10.3.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.3.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.3.1
1
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.3.1
1
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.3.1
1
jaedb/iris:latest048cfbf58d57
ip-address@9.0.5
10.3.1
1
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.3.1
1
jesec/flood:4.6.060bd59cfb4eb
ip-address@6.4.0
10.3.1
1
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.3.1
1
jesec/rtorrent-flood:latestf0c894ec459e
ip-address@6.4.0
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.