StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
487
of 17,781 indexed, latest versions
Container images
506
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 487 of 17,781 indexed charts deploy, on 506 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1506
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

487 by stars
ChartLatestAffected imagesRadar Score
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ip-address@9.0.5
10.3.1

Open the chart page →

4,880
homepagealareira1.0.11 of 1See more

homepage alareira 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:latest753eeb0cc22a
ip-address@10.1.0
10.3.1

Open the chart page →

352
cross-seedalekcVerified publisher7.19.01 of 1See more

cross-seed alekc 7.19.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.3.1

Open the chart page →

1,384
excalidashalekcVerified publisher1.4.01 of 2See more

excalidash alekc 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
ip-address@9.0.5
10.3.1

Open the chart page →

904
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.3.1

Open the chart page →

5,558
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
ip-address@10.1.0
10.3.1

Open the chart page →

690
argonix-apiargonix0.2.01 of 4See more

argonix-api argonix 0.2.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0b6a67099e4c5
ip-address@9.0.5
10.3.1

Open the chart page →

4,923
assemblylineassemblylineVerified publisher7.4.171 of 12See more

assemblyline assemblyline 7.4.17

1 of the 12 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cccs/assemblyline-ui-frontend:4.7.4.stable174c8e4b6c0483
ip-address@10.1.0
10.3.1

Open the chart page →

12,898
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.3.1

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wettyoss/wetty:latest7423b3d40ba2
ip-address@9.0.5
10.3.1

Open the chart page →

7,152
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.3.1

Open the chart page →

1,901
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.3.1

Open the chart page →

2,136
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
ip-address@10.0.1
10.3.1

Open the chart page →

1,168
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
ip-address@9.0.5
10.3.1
sysnet4admin/colosseum-prm:log5802bfcd7fed
ip-address@9.0.5
10.3.1

Open the chart page →

26,996
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
ip-address@6.4.0
10.3.1

Open the chart page →

1,477
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.3.1
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.3.1

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.3.1

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.3.1

Open the chart page →

1,306
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.3.1

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
ip-address@9.0.5
10.3.1

Open the chart page →

1,338
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.3.1

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
ip-address@9.0.5
10.3.1

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
ip-address@9.0.5
10.3.1

Open the chart page →

1,977
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ip-address@9.0.5
10.3.1

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
ip-address@5.9.4
10.3.1
countly/frontend:25.05.42acbc11499b6
ip-address@5.9.4
10.3.1

Open the chart page →

7,295
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ip-address@10.1.0
10.3.1

Open the chart page →

1,947
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.3.1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.3.1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.3.1

Open the chart page →

18,293
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
ip-address@9.0.5
10.3.1

Open the chart page →

2,184
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.3.1

Open the chart page →

408
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
ip-address@9.0.5
10.3.1

Open the chart page →

3,868
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
ip-address@9.0.5
10.3.1

Open the chart page →

1,527
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.3.1

Open the chart page →

1,598
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
ip-address@9.0.5
10.3.1

Open the chart page →

8,368
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.3.1

Open the chart page →

14,559
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
ip-address@6.4.0
10.3.1

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
cspconsole/report-processor:1.0.279a2d8840bfdf
ip-address@10.1.0
10.3.1

Open the chart page →

12,274
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.3.1

Open the chart page →

551
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.3.1

Open the chart page →

22,193
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.3.1

Open the chart page →

6,172
dbgatedbgate-helm-chartVerified publisher0.1.81 of 1See more

dbgate dbgate-helm-chart 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.3f2dc7423ea88
ip-address@10.1.0
10.3.1

Open the chart page →

1,397
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

1,138
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

1,138
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

1,138
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.02 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
decisionrules/business-intelligence:latest1135a6d4f09b
ip-address@10.1.0
10.3.1
decisionrules/server:latestf38d8571fa06
ip-address@10.1.0
10.3.1

Open the chart page →

2,685
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
ip-address@9.0.5
10.3.1

Open the chart page →

4,509
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
ip-address@10.1.0
10.3.1

Open the chart page →

1,662
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
ip-address@9.0.5
10.3.1

Open the chart page →

2,529
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
ip-address@9.0.5
10.3.1

Open the chart page →

1,264

Container images carrying it

506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.3.1
1
mauricenino/dashdot:5.9.2236997816917
ip-address@9.0.5
10.3.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.3.1
1
mcpuse/inspector:latest91b25e3eb604
ip-address@10.1.0
10.3.1
1
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.3.1
1
mishtinetwork/operator:latestbb3fe67a5f7c
ip-address@9.0.5
10.3.1
1
misskey/misskey:12.110.1e08b7c478093
ip-address@7.1.0
10.3.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.3.1
1
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.3.1
1
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.3.1
1
moreillon/food-manager:lateste8fd856e593d
ip-address@9.0.5
10.3.1
1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.3.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.3.1
1
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.3.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.2.0
10.3.1
1
n8nio/n8n:1.33.1dd171d45102a
ip-address@9.0.5
10.3.1
1
neoskop/ixy:2.1.125152b474f54
ip-address@10.1.0
10.3.1
1
nocodb/nocodb:0.258.06779a4ddedf2
ip-address@9.0.5
10.3.1
1
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.3.1
1
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.2.0
10.3.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.3.1
1
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.3.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.3.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.3.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.3.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.3.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.3.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.3.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.3.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.3.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.3.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.3.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.3.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.3.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.3.1
1
oneuptime/nginx:release6da7de4fc0f3
ip-address@10.2.0
10.3.1
1
oneuptime/probe:release6b2d98713711
ip-address@10.2.0
10.3.1
1
oneuptime/runner:release4accc516d800
ip-address@10.2.0
10.3.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.3.1
1
opencti/platform:7.260910.0186fc757c3eb
ip-address@10.1.0
10.3.1
1
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.3.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.3.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.3.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.3.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.3.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.3.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.3.1
1
otwld/velero-ui:0.10.2d1954b759e47
ip-address@10.2.0
10.3.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.3.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.2.0
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.