StackRadar

CVE-2026-69198

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
116
deployed by those charts
Fix available
1 of 1
affected package

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 116 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.1.1, 10.2.010.2.2116
OSV records
GHSA-4xrf-jv44-h6hh

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.2.2

Open the chart page →

2,522
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@10.2.0
10.2.2

Open the chart page →

3,833
discord-botxxczakiVerified publisher0.27.51 of 2See more

discord-bot xxczaki 0.27.5

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
ip-address@10.2.0
10.2.2

Open the chart page →

474
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
ip-address@10.1.1
10.2.2

Open the chart page →

1,411
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.2.2

Open the chart page →

1,248
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.2.0
10.2.2

Open the chart page →

1,216
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.2.0
10.2.2

Open the chart page →

523
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.2.2

Open the chart page →

1,901
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2

Open the chart page →

14,352
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.2.2

Open the chart page →

408
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.2.2

Open the chart page →

551
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
ip-address@10.2.0
10.2.2

Open the chart page →

4,046
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.2.2

Open the chart page →

7,459
clickhouse-monitoringduyet0.1.21 of 2See more

clickhouse-monitoring duyet 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.2.2

Open the chart page →

1,049
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.2.2

Open the chart page →

687
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.2.0
10.2.2

Open the chart page →

975
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.2.2

Open the chart page →

30,159
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.2.2

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.2.2

Open the chart page →

839
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.2.2

Open the chart page →

2,891
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
ip-address@10.2.0
10.2.2

Open the chart page →

2,522
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2

Open the chart page →

7,368
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.2.2

Open the chart page →

6,851
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.2.2

Open the chart page →

1,053
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.2

Open the chart page →

9,047
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.2.2

Open the chart page →

7,633
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.2.2

Open the chart page →

739
homarrhelmforgeVerified publisher1.2.81 of 1See more

homarr helmforge 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.2.2

Open the chart page →

435
matterbridgehelmforgeVerified publisher1.0.21 of 1See more

matterbridge helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.2.2

Open the chart page →

895
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.2.2

Open the chart page →

792
opencuthelmforgeVerified publisher1.1.91 of 5See more

opencut helmforge 1.1.9

1 of the 5 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.2.2

Open the chart page →

3,726
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.2.2

Open the chart page →

2,538
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.2.2

Open the chart page →

453
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.2.2
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.2.2

Open the chart page →

3,025
twentyhelmforgeVerified publisher1.0.01 of 5See more

twenty helmforge 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.2.2

Open the chart page →

2,818
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.2.2

Open the chart page →

8,967
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.2.0
10.2.2

Open the chart page →

3,436
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.2.2

Open the chart page →

424
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.2.2

Open the chart page →

2,149
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.2.0
10.2.2

Open the chart page →

3,092
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.2.2

Open the chart page →

2,437
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.2.2

Open the chart page →

12,062
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.2.2

Open the chart page →

2,756
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.2.2

Open the chart page →

2,149
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.2.2

Open the chart page →

33,242
libredb-studiolibredb-studio-oci0.1.631 of 1See more

libredb-studio libredb-studio-oci 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
ip-address@10.2.0
10.2.2

Open the chart page →

1,222
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.2.0
10.2.2

Open the chart page →

1,809
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.2.2

Open the chart page →

33,242
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@10.2.0
10.2.2
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@10.2.0
10.2.2

Open the chart page →

2,774

Container images carrying it

116 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@10.2.0
10.2.2
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
ip-address@10.2.0
10.2.2
1
ghcr.io/microboxlabs/miot-dashboard-server:latest19b910920ab1
ip-address@10.2.0
10.2.2
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
ip-address@10.2.0
10.2.2
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
ip-address@10.2.0
10.2.2
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.2.2
1
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
ip-address@10.2.0
10.2.2
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.2.2
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.2.2
1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.2.2
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.2.2
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.2.2
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
ip-address@10.1.1
10.2.2
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
ip-address@10.2.0
10.2.2
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.2.2
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
ip-address@10.2.0
10.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.