StackRadar

CVE-2026-69198

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
116
deployed by those charts
Fix available
1 of 1
affected package

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 116 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.1.1, 10.2.010.2.2116
OSV records
GHSA-4xrf-jv44-h6hh

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.2.0
10.2.2

Open the chart page →

1,038
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.2.2

Open the chart page →

30,159
backstagebackstageOfficialVerified publisher2.10.11 of 1See more

backstage backstage 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:latest792e262ea504
ip-address@10.2.0
10.2.2

Open the chart page →

1,195
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.2.2
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.2.0
10.2.2
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.2.0
10.2.2
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.2.0
10.2.2

Open the chart page →

12,279
opensearch-dashboardsopensearch-project-helm-chartsVerified publisher3.8.01 of 1See more

opensearch-dashboards opensearch-project-helm-charts 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.2.2

Open the chart page →

280
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
ip-address@10.2.0
10.2.2
penpotapp/mcp:2.17.284f3f07ead11
ip-address@10.2.0
10.2.2

Open the chart page →

4,314
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.2.2

Open the chart page →

1,091
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip-address@10.2.0
10.2.2

Open the chart page →

7,210
localstacklocalstack0.7.01 of 1See more

localstack localstack 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.2

Open the chart page →

2,156
oneuptimeoneuptimeOfficialVerified publisher13.0.43 of 7See more

oneuptime oneuptime 13.0.4

3 of the 7 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
oneuptime/nginx:release6da7de4fc0f3
ip-address@10.2.0
10.2.2
oneuptime/probe:release6b2d98713711
ip-address@10.2.0
10.2.2
oneuptime/runner:release4accc516d800
ip-address@10.2.0
10.2.2

Open the chart page →

11,192
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
ip-address@10.2.0
10.2.2

Open the chart page →

5,660
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
ip-address@10.2.0
10.2.2

Open the chart page →

3,004
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
ip-address@10.2.0
10.2.2

Open the chart page →

1,332
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.2.2

Open the chart page →

10,775
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
ip-address@10.2.0
10.2.2

Open the chart page →

2,977
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.2

Open the chart page →

2,938
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
ip-address@10.1.1
10.2.2

Open the chart page →

5,564
kuttchristianhuthVerified publisher9.10.11 of 3See more

kutt christianhuth 9.10.1

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
kutt/kutt:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.2.2

Open the chart page →

454
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epam/ai-dial-chat:0.49.0bd6b13695cdc
ip-address@10.2.0
10.2.2

Open the chart page →

2,163
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.2.2
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ip-address@10.2.0
10.2.2

Open the chart page →

9,460
libredb-studiolibredb-studioVerified publisher0.1.631 of 1See more

libredb-studio libredb-studio 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
ip-address@10.2.0
10.2.2

Open the chart page →

1,222
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
ip-address@10.2.0
10.2.2

Open the chart page →

725
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
ip-address@10.2.0
10.2.2

Open the chart page →

1,870
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
ip-address@10.2.0
10.2.2

Open the chart page →

1,717
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
shieldsio/shields:nextfa194b446e42
ip-address@10.2.0
10.2.2

Open the chart page →

1,798
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
ip-address@10.2.0
10.2.2

Open the chart page →

5,218
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.2

Open the chart page →

977
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.2.2

Open the chart page →

8,491
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.2.2

Open the chart page →

1,044
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.2.2

Open the chart page →

5,880
kinesisaws-kinesis-local0.8.01 of 1See more

kinesis aws-kinesis-local 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.2.2

Open the chart page →

360
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.2.2

Open the chart page →

1,991
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.2.2

Open the chart page →

2,360
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.2.2

Open the chart page →

101
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.2.2

Open the chart page →

2,173
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.2.2

Open the chart page →

38,346
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.2.2

Open the chart page →

9,205
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.2.2

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ip-address@10.2.0
10.2.2

Open the chart page →

1,722
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.2.2

Open the chart page →

1,882
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.2.2

Open the chart page →

1,322
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.2.2

Open the chart page →

1,091
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.2.2

Open the chart page →

2,575
kuttone-acre-fundVerified publisher0.2.51 of 1See more

kutt one-acre-fund 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
kutt/kutt:latestfa3d24a89b04
ip-address@10.2.0
10.2.2

Open the chart page →

454
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.2.2

Open the chart page →

7,035
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.2.0
10.2.2

Open the chart page →

31,844
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
ip-address@10.2.0
10.2.2

Open the chart page →

3,059
wg-easyslybase-wg-easyVerified publisher1.2.01 of 1See more

wg-easy slybase-wg-easy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:15.4.00e7bc9d34e86
ip-address@10.2.0
10.2.2

Open the chart page →

725
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.2.0
10.2.2

Open the chart page →

18,075
switcher-apiswitcherapiOfficialVerified publisher1.3.52 of 3See more

switcher-api switcherapi 1.3.5

2 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
trackerforce/switcher-api:latest28ee0c4e0b88
ip-address@10.2.0
10.2.2
trackerforce/switcher-resolver-node:latest67e2c261f7b4
ip-address@10.2.0
10.2.2

Open the chart page →

623

Container images carrying it

116 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.2.2
1
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.2.2
1
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.2.2
1
n8nio/n8n:2.25.7761374d4eb84
ip-address@10.1.1
10.2.2
1
n8nio/n8n:2.36.8cfe2704ff858
ip-address@10.2.0
10.2.2
1
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.2.0
10.2.2
1
nodered/node-red:5.0.7a649dd711d55
ip-address@10.2.0
10.2.2
1
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.2.0
10.2.2
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
ip-address@10.2.0
10.2.2
1
oneuptime/nginx:release6da7de4fc0f3
ip-address@10.2.0
10.2.2
1
oneuptime/probe:release6b2d98713711
ip-address@10.2.0
10.2.2
1
oneuptime/runner:release4accc516d800
ip-address@10.2.0
10.2.2
1
otwld/velero-ui:0.10.2d1954b759e47
ip-address@10.2.0
10.2.2
1
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.2.0
10.2.2
1
penpotapp/exporter:2.17.272a8061e8806
ip-address@10.2.0
10.2.2
1
penpotapp/mcp:2.17.284f3f07ead11
ip-address@10.2.0
10.2.2
1
rocketchat/account-service:8.6.144af8ac4e711
ip-address@10.2.0
10.2.2
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
ip-address@10.2.0
10.2.2
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
ip-address@10.2.0
10.2.2
1
rocketchat/presence-service:8.6.1c1170bdfe797
ip-address@10.2.0
10.2.2
1
saidsef/aws-kinesis-local:v2026.0667025e3a163e
ip-address@10.2.0
10.2.2
1
shieldsio/shields:nextfa194b446e42
ip-address@10.2.0
10.2.2
1
supabase/storage-api:v1.60.4c8eb9858eafe
ip-address@10.2.0
10.2.2
1
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.2.2
1
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.2.2
1
trackerforce/switcher-api:latest28ee0c4e0b88
ip-address@10.2.0
10.2.2
1
trackerforce/switcher-resolver-node:latest67e2c261f7b4
ip-address@10.2.0
10.2.2
1
treskon/portrait-ui:DEV-lateste7970783bc8d
ip-address@10.2.0
10.2.2
1
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.2.2
1
veecode/devportalc443520aebf7
ip-address@10.2.0
10.2.2
1
wsjbr/duplistatus:1.4.25e594f5f09f6
ip-address@10.2.0
10.2.2
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
ip-address@10.2.0
10.2.2
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.2.2
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.2.2
1
ghcr.io/backstage/backstage:latest792e262ea504
ip-address@10.2.0
10.2.2
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.2.2
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
ip-address@10.2.0
10.2.2
1
ghcr.io/cameri/nostream:main8726533b9e69
ip-address@10.2.0
10.2.2
1
ghcr.io/data-fair/portals:18b621866ceb2
ip-address@10.2.0
10.2.2
1
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
ip-address@10.2.0
10.2.2
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.2.2
1
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.2.2
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.2.2
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.2.2
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
ip-address@10.2.0
10.2.2
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.2.2
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
ip-address@10.2.0
10.2.2
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.2.2
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
ip-address@10.2.0
10.2.2
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@10.2.0
10.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.