StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
487
of 17,781 indexed, latest versions
Container images
506
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 487 of 17,781 indexed charts deploy, on 506 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1506
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

487 by stars
ChartLatestAffected imagesRadar Score
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
ip-address@10.2.0
10.3.1

Open the chart page →

725
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
ip-address@10.1.0
10.3.1

Open the chart page →

7,146
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
ip-address@9.0.5
10.3.1

Open the chart page →

7,450
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
ip-address@9.0.5
10.3.1

Open the chart page →

1,152
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
ip-address@9.0.5
10.3.1

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.03 of 10See more

cosmo cosmo-platform 0.20.0

3 of the 10 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
ip-address@9.0.5
10.3.1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
ip-address@9.0.5
10.3.1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
ip-address@9.0.5
10.3.1

Open the chart page →

28,839
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.3.1

Open the chart page →

3,451
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
ip-address@10.2.0
10.3.1

Open the chart page →

1,870
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
ip-address@10.2.0
10.3.1

Open the chart page →

1,717
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
instill/console:0.68.54cd70e2df5c6
ip-address@9.0.5
10.3.1

Open the chart page →

30,816
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
aaronshaf/dynamodb-admin:latestac41724cd997
ip-address@10.1.0
10.3.1

Open the chart page →

1,304
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
shieldsio/shields:nextfa194b446e42
ip-address@10.2.0
10.3.1

Open the chart page →

1,798
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
ip-address@10.1.0
10.3.1

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
ip-address@9.0.5
10.3.1

Open the chart page →

2,635
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
ip-address@10.1.0
10.3.1

Open the chart page →

5,218
pacmanpacmanVerified publisher2.0.21 of 2See more

pacman pacman 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/shuguet/pacman:latesta0ec71732c3c
ip-address@10.1.0
10.3.1

Open the chart page →

638
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
ip-address@9.0.5
10.3.1

Open the chart page →

2,702
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.3.1

Open the chart page →

977
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
ip-address@10.1.0
10.3.1

Open the chart page →

9,770
feedbacksystemthm-mni-iiVerified publisher0.47.13 of 10See more

feedbacksystem thm-mni-ii 0.47.1

3 of the 10 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
ip-address@9.0.5
10.3.1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
ip-address@9.0.5
10.3.1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
ip-address@9.0.5
10.3.1

Open the chart page →

28,534
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.3.1

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.3.1

Open the chart page →

4,016
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.3.1

Open the chart page →

1,044
agentareaagentareaVerified publisher0.0.182 of 16See more

agentarea agentarea 0.0.18

2 of the 16 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
agentarea/agentarea-frontend:latest2098a9d7b1fe
ip-address@10.1.0
10.3.1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
ip-address@10.1.0
10.3.1

Open the chart page →

14,914
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.3.1

Open the chart page →

5,880
dbgateappscodeVerified publisher2026.3.301 of 1See more

dbgate appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.0-alpine287077002446
ip-address@9.0.5
10.3.1

Open the chart page →

458
kinesisaws-kinesis-local0.8.01 of 1See more

kinesis aws-kinesis-local 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.3.1

Open the chart page →

360
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.3.1

Open the chart page →

1,991
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.3.1

Open the chart page →

1,843
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.3.1

Open the chart page →

2,360
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.3.1

Open the chart page →

101
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.3.1

Open the chart page →

1,143
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.3.1

Open the chart page →

2,173
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/data-fair/notify:3c739b74dabb0
ip-address@9.0.5
10.3.1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.3.1

Open the chart page →

38,346
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.3.1

Open the chart page →

9,205
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.3.1

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ip-address@10.2.0
10.3.1

Open the chart page →

1,722
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.3.1

Open the chart page →

1,882
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
ip-address@9.0.5
10.3.1

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-69192.

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
ip-address@9.0.5
10.3.1

Open the chart page →

1,442
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ip-address@9.0.5
10.3.1

Open the chart page →

11,458
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
ip-address@10.1.0
10.3.1

Open the chart page →

3,123
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
globalping/globalping-probe:latest8acbd23009fd
ip-address@10.1.0
10.3.1

Open the chart page →

518
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
ip-address@10.1.0
10.3.1

Open the chart page →

2,000
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.3.1

Open the chart page →

4,196
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
ip-address@10.1.0
10.3.1

Open the chart page →

12,397
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ip-address@9.0.5
10.3.1

Open the chart page →

15,712
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.3.1

Open the chart page →

5,228
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.3.1

Open the chart page →

1,322

Container images carrying it

506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.3.1
1
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.3.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.3.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1
1
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.3.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.3.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.3.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.3.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.3.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.3.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.3.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.3.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.3.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.3.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.3.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1
1
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.3.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.3.1
1
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.3.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.3.1
1
library/node:22-bookworm-slim83f487e0a634
ip-address@10.1.0
10.3.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.3.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.3.1
1
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
1
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.3.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.3.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.3.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.3.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:13d632903e6af
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.3.1
1
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.