StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
488
of 17,787 indexed, latest versions
Container images
507
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 488 of 17,787 indexed charts deploy, on 507 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1507
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

488 by stars
ChartLatestAffected imagesRadar Score
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
ip-address@9.0.5
10.3.1

Open the chart page →

1,653
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
ip-address@9.0.5
10.3.1

Open the chart page →

4,860
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
ip-address@8.1.0
10.3.1

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
ip-address@10.0.1
10.3.1

Open the chart page →

3,972
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.3.1
supabase/studio:latest94a2a9d2906e
ip-address@10.1.0
10.3.1

Open the chart page →

9,556
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
ip-address@9.0.5
10.3.1

Open the chart page →

11,648
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.3.1

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.3.1

Open the chart page →

5,604
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
ip-address@9.0.5
10.3.1

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.3.1

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.3.1

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1

Open the chart page →

5,535
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
ip-address@9.0.5
10.3.1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
ip-address@9.0.5
10.3.1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
ip-address@9.0.5
10.3.1

Open the chart page →

6,994
altinnendata-apptumogroup0.1.171See more

altinnendata-app tumogroup 0.1.17

1 container image this version deploys carries CVE-2026-69192.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.9.1c2707839d8a3
ip-address@9.0.5
10.3.1

Open the chart page →

nstuning-apptumogroup0.1.181See more

nstuning-app tumogroup 0.1.18

1 container image this version deploys carries CVE-2026-69192.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.113a6795bf36da
ip-address@9.0.5
10.3.1

Open the chart page →

twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.3.1

Open the chart page →

5,550
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.3.1

Open the chart page →

352
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
ip-address@10.1.0
10.3.1

Open the chart page →

2,028
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
ip-address@9.0.5
10.3.1

Open the chart page →

929
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
ip-address@9.0.5
10.3.1

Open the chart page →

2,620
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.3.1

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.3.1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
ip-address@9.0.5
10.3.1

Open the chart page →

4,768
devportalveecode-platform-nextVerified publisher0.1.221See more

devportal veecode-platform-next 0.1.22

1 container image this version deploys carries CVE-2026-69192.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
ip-address@10.2.0
10.3.1

Open the chart page →

browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.3.1

Open the chart page →

4,305
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.3.1

Open the chart page →

2,076
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
ip-address@9.0.5
10.3.1

Open the chart page →

video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.3.1

Open the chart page →

1,961
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.3.1

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.3.1

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.3.1

Open the chart page →

5,484
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.3.1

Open the chart page →

1,616
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.3.1

Open the chart page →

280
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.3.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.3.1

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.3.1

Open the chart page →

14,100
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.3.1

Open the chart page →

9,381

Container images carrying it

507 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.3.1
1
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.3.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.3.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1
1
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.3.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.3.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.3.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.3.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.3.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.3.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.3.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.3.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.3.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.3.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.3.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1
1
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.3.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.3.1
1
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.3.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.3.1
1
library/node:22-bookworm-slim83f487e0a634
ip-address@10.1.0
10.3.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.3.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.3.1
1
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
1
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.3.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.3.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.3.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.3.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:13d632903e6af
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.3.1
1
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.