StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
487
of 17,781 indexed, latest versions
Container images
506
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 487 of 17,781 indexed charts deploy, on 506 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1506
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

487 by stars
ChartLatestAffected imagesRadar Score
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ip-address@9.0.5
10.3.1

Open the chart page →

3,806
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
ip-address@9.0.5
10.3.1

Open the chart page →

948
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ip-address@9.0.5
10.3.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.3.1

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
ip-address@10.1.0
10.3.1

Open the chart page →

4,018
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.3.1

Open the chart page →

7,633
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
ip-address@9.0.5
10.3.1

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.3.1

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ip-address@9.0.5
10.3.1

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ip-address@9.0.5
10.3.1

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
ip-address@10.1.0
10.3.1

Open the chart page →

2,463
homarrhelmforgeVerified publisher1.2.81 of 1See more

homarr helmforge 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.3.1

Open the chart page →

435
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.3.1

Open the chart page →

11,042
matterbridgehelmforgeVerified publisher1.0.21 of 1See more

matterbridge helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.3.1

Open the chart page →

895
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.3.1

Open the chart page →

792
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.3.1

Open the chart page →

9,653
opencuthelmforgeVerified publisher1.1.91 of 5See more

opencut helmforge 1.1.9

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.3.1

Open the chart page →

3,726
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.3.1

Open the chart page →

2,538
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.3.1

Open the chart page →

453
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.3.1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.3.1

Open the chart page →

3,025
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.3.1

Open the chart page →

6,012
twentyhelmforgeVerified publisher1.0.01 of 5See more

twenty helmforge 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.3.1

Open the chart page →

2,818
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
ip-address@10.1.0
10.3.1

Open the chart page →

30,099
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.3.1

Open the chart page →

25,017
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
ip-address@10.1.0
10.3.1

Open the chart page →

1,468
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
ip-address@5.9.4
10.3.1

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ip-address@9.0.5
10.3.1

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.3.1

Open the chart page →

3,407
multicaicoretechVerified publisher0.4.421 of 5See more

multica icoretech 0.4.42

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/multica-ai/multica-web:v0.4.43fc937fbbf8e5
ip-address@10.1.0
10.3.1

Open the chart page →

2,722
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
ip-address@9.0.5
10.3.1

Open the chart page →

3,154
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.3.1

Open the chart page →

8,967
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
ip-address@10.0.1
10.3.1

Open the chart page →

6,254
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
ip-address@10.0.1
10.3.1

Open the chart page →

1,235
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ip-address@9.0.5
10.3.1

Open the chart page →

11,812
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
ip-address@9.0.5
10.3.1

Open the chart page →

3,014
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.1.0
10.3.1

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.3.1

Open the chart page →

5,826
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.3.1

Open the chart page →

424
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.3.1

Open the chart page →

2,149
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
ip-address@9.0.5
10.3.1

Open the chart page →

914
github-exporterjkroepkeVerified publisher1.4.01 of 1See more

github-exporter jkroepke 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jkroepke/github_exporter:1.8.03d850992786d
ip-address@10.0.1
10.3.1

Open the chart page →

1,031
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
ip-address@9.0.5
10.3.1

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.03 of 8See more

shinsei-manager jtekt 0.2.0

3 of the 8 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.3.1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.3.1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
ip-address@9.0.5
10.3.1

Open the chart page →

63,461
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
ip-address@9.0.5
10.3.1

Open the chart page →

1,966
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
ip-address@9.0.5
10.3.1

Open the chart page →

2,611
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
ip-address@9.0.5
10.3.1

Open the chart page →

8,811
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ip-address@9.0.5
10.3.1

Open the chart page →

2,350
floodk8s-home-lab-repo7.3.01 of 1See more

flood k8s-home-lab-repo 7.3.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
jesec/flood:4.14.3c887dad96b40
ip-address@10.1.0
10.3.1

Open the chart page →

746
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.1.0
10.3.1

Open the chart page →

3,092
k8s-jacoco-operatork8s-jacoco-operator0.4.02 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

2 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.3.1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.3.1

Open the chart page →

2,437

Container images carrying it

506 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
maildev/maildev:2.2.1180ef51f65ee
ip-address@9.0.5
10.3.1
1
mauricenino/dashdot:5.9.2236997816917
ip-address@9.0.5
10.3.1
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.1.0
10.3.1
1
mcpuse/inspector:latest91b25e3eb604
ip-address@10.1.0
10.3.1
1
middlewareeng/middleware:0.3.1747d880812f1
ip-address@9.0.5
10.3.1
1
mishtinetwork/operator:latestbb3fe67a5f7c
ip-address@9.0.5
10.3.1
1
misskey/misskey:12.110.1e08b7c478093
ip-address@7.1.0
10.3.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
ip-address@9.0.5
10.3.1
1
moreillon/api-proxy:latestd7d4a5463525
ip-address@9.0.5
10.3.1
1
moreillon/camera-proxy:latestce60056b50c2
ip-address@9.0.5
10.3.1
1
moreillon/food-manager:lateste8fd856e593d
ip-address@9.0.5
10.3.1
1
moreillon/group-manager:latest3caa8f710ee0
ip-address@9.0.5
10.3.1
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.3.1
1
n8nio/n8n:1.86.08b39ed5a2de9
ip-address@9.0.5
10.3.1
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.2.0
10.3.1
1
n8nio/n8n:1.33.1dd171d45102a
ip-address@9.0.5
10.3.1
1
neoskop/ixy:2.1.125152b474f54
ip-address@10.1.0
10.3.1
1
nocodb/nocodb:0.258.06779a4ddedf2
ip-address@9.0.5
10.3.1
1
nocodb/nocodb:0.301.5d9516f0bf546
ip-address@9.0.5
10.3.1
1
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.2.0
10.3.1
1
nodered/node-red:4.1.2216e7403aab9
ip-address@10.1.0
10.3.1
1
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.3.1
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.1.0
10.3.1
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.3.1
1
oada/auth:4.0.0c0d077e79ef4
ip-address@9.0.5
10.3.1
1
oada/http-handler:4.0.0d87efe8ba4b0
ip-address@9.0.5
10.3.1
1
oada/rev-graph-update:4.0.0ebc8343f05ff
ip-address@9.0.5
10.3.1
1
oada/shares:4.0.0c6ffb4e8ed63
ip-address@9.0.5
10.3.1
1
oada/startup:4.0.0fc09495e2f3c
ip-address@9.0.5
10.3.1
1
oada/sync-handler:4.0.0b7a2cfc137cf
ip-address@9.0.5
10.3.1
1
oada/users:4.0.0b6c562fa5b1b
ip-address@9.0.5
10.3.1
1
oada/webhooks:4.0.06590c60de347
ip-address@9.0.5
10.3.1
1
oada/well-known:4.0.07943fde43b19
ip-address@9.0.5
10.3.1
1
oada/write-handler:4.0.08464c7f48aae
ip-address@9.0.5
10.3.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ip-address@10.0.1
10.3.1
1
oneuptime/nginx:release6da7de4fc0f3
ip-address@10.2.0
10.3.1
1
oneuptime/probe:release6b2d98713711
ip-address@10.2.0
10.3.1
1
oneuptime/runner:release4accc516d800
ip-address@10.2.0
10.3.1
1
openbas/caldera-server:5.1.0a277796d9724
ip-address@9.0.5
10.3.1
1
opencti/platform:7.260910.0186fc757c3eb
ip-address@10.1.0
10.3.1
1
opendatacube/wps:latest80df355a660b
ip-address@9.0.5
10.3.1
1
openmined/syft-frontend:0.9.5d11524a3854a
ip-address@9.0.5
10.3.1
1
openproject/hocuspocus:release-338001b288dc1359dfb5
ip-address@9.0.5
10.3.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.3.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
ip-address@6.4.0
10.3.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ip-address@6.4.0
10.3.1
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
ip-address@9.0.5
10.3.1
1
otwld/velero-ui:0.10.2d1954b759e47
ip-address@10.2.0
10.3.1
1
outlinewiki/outline:0.82.0494dfb9249a6
ip-address@9.0.5
10.3.1
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.2.0
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.