StackRadar

CVE-2026-69192

High

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
479
of 17,787 indexed, latest versions
Container images
497
deployed by those charts
Fix available
1 of 1
affected package

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Carried by container images the latest versions of 479 of 17,787 indexed charts deploy, on 497 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm5.9.4, 6.1.0, 6.4.0, 7.1.0+6 more10.3.1497
OSV records
GHSA-mwp4-54f8-5fhr

Charts affected

479 by stars
ChartLatestAffected imagesRadar Score
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.3.1

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
ip-address@9.0.5
10.3.1

Open the chart page →

5,604
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
ip-address@9.0.5
10.3.1

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ip-address@9.0.5
10.3.1

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
ip-address@5.9.4
10.3.1

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.3.1

Open the chart page →

5,535
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
ip-address@9.0.5
10.3.1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
ip-address@9.0.5
10.3.1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
ip-address@9.0.5
10.3.1

Open the chart page →

6,994
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.3.1

Open the chart page →

5,550
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
ip-address@10.1.0
10.3.1

Open the chart page →

352
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
ip-address@10.1.0
10.3.1

Open the chart page →

2,028
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
ip-address@9.0.5
10.3.1

Open the chart page →

929
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
ip-address@9.0.5
10.3.1

Open the chart page →

2,620
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
ip-address@9.0.5
10.3.1

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
ip-address@10.1.0
10.3.1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
ip-address@9.0.5
10.3.1

Open the chart page →

4,768
devportalveecode-platform-nextVerified publisher0.1.221See more

devportal veecode-platform-next 0.1.22

1 container image this version deploys carries CVE-2026-69192.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
ip-address@10.2.0
10.3.1

Open the chart page →

browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.3.1

Open the chart page →

4,305
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.3.1

Open the chart page →

2,076
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.3.1

Open the chart page →

1,961
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ip-address@9.0.5
10.3.1

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ip-address@9.0.5
10.3.1

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
ip-address@6.4.0
10.3.1

Open the chart page →

5,484
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
ip-address@10.1.0
10.3.1

Open the chart page →

1,616
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.3.1

Open the chart page →

280
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
ip-address@10.1.0
10.3.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@5.9.4
10.3.1

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ip-address@9.0.5
10.3.1

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
ip-address@9.0.5
10.3.1

Open the chart page →

14,100
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-69192.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ip-address@6.4.0
10.3.1

Open the chart page →

9,381

Container images carrying it

497 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
ip-address@10.1.0
10.3.1
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
ip-address@10.1.0
10.3.1
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
ip-address@9.0.5
10.3.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
ip-address@9.0.5
10.3.1
1
ghcr.io/backstage/backstage:latest792e262ea504
ip-address@10.2.0
10.3.1
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
ip-address@9.0.5
10.3.1
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
ip-address@9.0.5
10.3.1
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
ip-address@9.0.5
10.3.1
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ip-address@9.0.5
10.3.1
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.3.1
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.3.1
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
ip-address@10.1.0
10.3.1
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
ip-address@9.0.5
10.3.1
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
ip-address@9.0.5
10.3.1
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
ip-address@9.0.5
10.3.1
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
ip-address@9.0.5
10.3.1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ip-address@9.0.5
10.3.1
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
ip-address@10.1.0
10.3.1
1
ghcr.io/cameri/nostream:main8726533b9e69
ip-address@10.2.0
10.3.1
1
ghcr.io/colanode/server:latest7006cac874fd
ip-address@10.1.0
10.3.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ip-address@9.0.5
10.3.1
1
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
ip-address@9.0.5
10.3.1
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ip-address@10.0.1
10.3.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ip-address@9.0.5
10.3.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
ip-address@9.0.5
10.3.1
1
ghcr.io/data-fair/notify:3c739b74dabb0
ip-address@9.0.5
10.3.1
1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.3.1
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.3.1
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.3.1
1
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.3.1
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.3.1
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
ip-address@9.0.5
10.3.1
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
ip-address@9.0.5
10.3.1
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ip-address@9.0.5
10.3.1
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ip-address@9.0.5
10.3.1
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ip-address@9.0.5
10.3.1
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.3.1
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
ip-address@10.1.0
10.3.1
1
ghcr.io/gethomepage/homepage:v2.3.0f82027665453
ip-address@10.1.0
10.3.1
1
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
ip-address@9.0.5
10.3.1
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
ip-address@10.1.0
10.3.1
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
ip-address@9.0.5
10.3.1
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
ip-address@10.2.0
10.3.1
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.3.1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
ip-address@9.0.5
10.3.1
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ip-address@9.0.5
10.3.1
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
ip-address@9.0.5
10.3.1
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
ip-address@10.1.0
10.3.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ip-address@9.0.5
10.3.1
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
ip-address@9.0.5
10.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.