StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
487
of 17,781 indexed, latest versions
Container images
506
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 487 of 17,781 indexed charts deploy, on 506 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1506
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

487 by stars
ChartLatestAffected imagesRadar Score
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.3.1

Open the chart page →

4,880
homepagealareira1.0.11 of 1See more

homepage alareira 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:latest753eeb0cc22a
ip-address@10.1.0
10.3.1

Open the chart page →

352
cross-seedalekcVerified publisher7.19.01 of 1See more

cross-seed alekc 7.19.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.3.1

Open the chart page →

1,384
excalidashalekcVerified publisher1.4.01 of 2See more

excalidash alekc 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@9.0.5
10.3.1

Open the chart page →

904
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.3.1

Open the chart page →

5,558
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
ip-address@10.1.0
10.3.1

Open the chart page →

690
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0b6a67099e4c5
ip-address@9.0.5
10.3.1

Open the chart page →

4,923
assemblylineassemblylineVerified publisher7.4.171 of 12See more

assemblyline assemblyline 7.4.17

1 of the 12 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cccs/assemblyline-ui-frontend:4.7.4.stable174c8e4b6c0483
ip-address@10.1.0
10.3.1

Open the chart page →

12,898
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.3.1

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wettyoss/wetty:latest7423b3d40ba2
ip-address@9.0.5
10.3.1

Open the chart page →

7,152
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.3.1

Open the chart page →

1,901
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.3.1

Open the chart page →

2,136
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
ip-address@10.0.1
10.3.1

Open the chart page →

1,168
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.3.1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.3.1

Open the chart page →

26,996
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.3.1

Open the chart page →

1,477
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.3.1
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.3.1

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.3.1

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.3.1

Open the chart page →

1,306
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.3.1

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.3.1

Open the chart page →

1,338
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.3.1

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.3.1

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ip-address@9.0.5
10.3.1

Open the chart page →

1,977
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
ip-address@5.9.4
10.3.1
countly/frontend:25.05.42acbc11499b6
ip-address@5.9.4
10.3.1

Open the chart page →

7,295
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ip-address@10.1.0
10.3.1

Open the chart page →

1,947
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.3.1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.3.1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.3.1

Open the chart page →

18,293
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.3.1

Open the chart page →

2,184
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.3.1

Open the chart page →

408
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
ip-address@9.0.5
10.3.1

Open the chart page →

3,868
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.3.1

Open the chart page →

1,527
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.3.1

Open the chart page →

1,598
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.3.1

Open the chart page →

8,368
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.3.1

Open the chart page →

14,559
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
ip-address@6.4.0
10.3.1

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cspconsole/report-processor:1.0.279a2d8840bfdf
ip-address@10.1.0
10.3.1

Open the chart page →

12,274
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.3.1

Open the chart page →

551
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.3.1

Open the chart page →

22,193
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.3.1

Open the chart page →

6,172
dbgatedbgate-helm-chartVerified publisher0.1.81 of 1See more

dbgate dbgate-helm-chart 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.3f2dc7423ea88
ip-address@10.1.0
10.3.1

Open the chart page →

1,397
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

1,138
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

1,138
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

1,138
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.02 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/business-intelligence:latest1135a6d4f09b
ip-address@10.1.0
10.3.1
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

2,685
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
ip-address@9.0.5
10.3.1

Open the chart page →

4,509
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.3.1

Open the chart page →

1,662
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.3.1

Open the chart page →

2,529
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
ip-address@9.0.5
10.3.1

Open the chart page →

1,264

Container images carrying it

506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.3.1
1
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.3.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.3.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1
1
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.3.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.3.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.3.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.3.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.3.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.3.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.3.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.3.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.3.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.3.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.3.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1
1
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.3.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.3.1
1
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.3.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.3.1
1
library/node:22-bookworm-slim83f487e0a634
ip-address@10.1.0
10.3.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.3.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.3.1
1
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
1
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.3.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.3.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.3.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.3.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:13d632903e6af
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.3.1
1
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.