StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
487
of 17,781 indexed, latest versions
Container images
506
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 487 of 17,781 indexed charts deploy, on 506 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1506
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

487 by stars
ChartLatestAffected imagesRadar Score
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1

Open the chart page →

3,806
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1

Open the chart page →

948
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.3.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.3.1

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.1.0
10.3.1

Open the chart page →

4,018
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.3.1

Open the chart page →

7,633
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.3.1

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.3.1

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.3.1

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.3.1

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1

Open the chart page →

2,463
homarrhelmforgeVerified publisher1.2.81 of 1See more

homarr helmforge 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.3.1

Open the chart page →

435
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.3.1

Open the chart page →

11,042
matterbridgehelmforgeVerified publisher1.0.21 of 1See more

matterbridge helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1

Open the chart page →

895
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.3.1

Open the chart page →

792
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.3.1

Open the chart page →

9,653
opencuthelmforgeVerified publisher1.1.91 of 5See more

opencut helmforge 1.1.9

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.3.1

Open the chart page →

3,726
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.3.1

Open the chart page →

2,538
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.3.1

Open the chart page →

453
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.3.1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.3.1

Open the chart page →

3,025
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.3.1

Open the chart page →

6,012
twentyhelmforgeVerified publisher1.0.01 of 5See more

twenty helmforge 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.3.1

Open the chart page →

2,818
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1

Open the chart page →

30,099
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.3.1

Open the chart page →

25,017
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.3.1

Open the chart page →

1,468
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.3.1

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.3.1

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.3.1

Open the chart page →

3,407
multicaicoretechVerified publisher0.4.421 of 5See more

multica icoretech 0.4.42

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/multica-ai/multica-web:v0.4.43fc937fbbf8e5
ip-address@10.1.0
10.3.1

Open the chart page →

2,722
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.3.1

Open the chart page →

3,154
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.3.1

Open the chart page →

8,967
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.3.1

Open the chart page →

6,254
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.3.1

Open the chart page →

1,235
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.3.1

Open the chart page →

11,812
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
ip-address@9.0.5
10.3.1

Open the chart page →

3,014
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.3.1

Open the chart page →

5,826
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.3.1

Open the chart page →

424
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.3.1

Open the chart page →

2,149
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1

Open the chart page →

914
github-exporterjkroepkeVerified publisher1.4.01 of 1See more

github-exporter jkroepke 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1

Open the chart page →

1,031
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.3.1

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.03 of 8See more

shinsei-manager jtekt 0.2.0

3 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.3.1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.3.1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.3.1

Open the chart page →

63,461
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.3.1

Open the chart page →

1,966
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.3.1

Open the chart page →

2,611
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.3.1

Open the chart page →

8,811
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.3.1

Open the chart page →

2,350
floodk8s-home-lab-repo7.3.01 of 1See more

flood k8s-home-lab-repo 7.3.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.3.1

Open the chart page →

746
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1

Open the chart page →

3,092
k8s-jacoco-operatork8s-jacoco-operator0.4.02 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.3.1

Open the chart page →

2,437

Container images carrying it

506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1
1
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1
1
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.3.1
1
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1
1
joplin/server:3.0-beta52af57880c0e
ip-address@9.0.5
10.3.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.3.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1
1
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.3.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ip-address@10.0.1
10.3.1
1
laly9999/node-app:1dd0e503913e1
ip-address@9.0.5
10.3.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
ip-address@9.0.5
10.3.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
ip-address@9.0.5
10.3.1
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.3.1
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.3.1
1
langgenius/dify-web:1.16.187dd47e4e28f
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:0.6.11a2a294743634
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ip-address@9.0.5
10.3.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
ip-address@9.0.5
10.3.1
1
lbenicio/helm-pilot:0.2.54594a2632510
ip-address@10.1.0
10.3.1
1
lbenicio/stremio-web:latest732f9003de33
ip-address@10.1.0
10.3.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ip-address@9.0.5
10.3.1
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1
1
library/ghost:6.25.12654b1e90413
ip-address@10.1.0
10.3.1
1
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.3.1
1
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.3.1
1
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
ip-address@9.0.5
10.3.1
1
library/node:22-bookworm-slim83f487e0a634
ip-address@10.1.0
10.3.1
1
library/node:18-alpine8d6421d663b4
ip-address@9.0.5
10.3.1
1
library/node:208f693eaa7e0a
ip-address@9.0.5
10.3.1
1
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
1
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.3.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.3.1
1
lissy93/networking-toolbox:latest700862839553
ip-address@9.0.5
10.3.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-consumer:latest02225e77d316
ip-address@9.0.5
10.3.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ip-address@10.1.0
10.3.1
1
litlyx/litlyx-producer:latest10407f36613f
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:13d632903e6af
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.1.0
10.3.1
1
louislam/uptime-kuma:1.23.1396510915e6be
ip-address@9.0.5
10.3.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ip-address@10.0.1
10.3.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ip-address@9.0.5
10.3.1
1
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1
1
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.