StackRadar

CVE-2026-69198

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
116
deployed by those charts
Fix available
1 of 1
affected package

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 116 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.1.1, 10.2.010.2.2116
OSV records
GHSA-4xrf-jv44-h6hh

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
ip-address@10.2.0
10.2.2

Open the chart page →

2,522
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
ip-address@10.2.0
10.2.2

Open the chart page →

3,833
discord-botxxczakiVerified publisher0.27.51 of 2See more

discord-bot xxczaki 0.27.5

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
ip-address@10.2.0
10.2.2

Open the chart page →

474
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
ip-address@10.1.1
10.2.2

Open the chart page →

1,411
lhciadnoctemVerified publisher0.1.01 of 1See more

lhci adnoctem 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
ip-address@10.2.0
10.2.2

Open the chart page →

1,248
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
ip-address@10.2.0
10.2.2

Open the chart page →

1,216
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.2.0
10.2.2

Open the chart page →

523
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.2.2

Open the chart page →

1,901
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2

Open the chart page →

14,352
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.2.2

Open the chart page →

408
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
ip-address@10.2.0
10.2.2

Open the chart page →

551
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
ip-address@10.2.0
10.2.2

Open the chart page →

4,046
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
ip-address@10.2.0
10.2.2

Open the chart page →

7,459
clickhouse-monitoringduyet0.1.21 of 2See more

clickhouse-monitoring duyet 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
ip-address@10.2.0
10.2.2

Open the chart page →

1,049
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.2.2

Open the chart page →

687
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
ip-address@10.2.0
10.2.2

Open the chart page →

975
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.2.2

Open the chart page →

30,159
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.2.2

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.2.2

Open the chart page →

839
assertoorethereum-helm-chartsVerified publisher1.2.01 of 1See more

assertoor ethereum-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.2.2

Open the chart page →

2,891
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
ip-address@10.2.0
10.2.2

Open the chart page →

2,522
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2

Open the chart page →

7,368
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.2.2

Open the chart page →

6,851
redis-uigin0.0.11 of 1See more

redis-ui gin 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.2.2

Open the chart page →

1,053
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.2

Open the chart page →

9,047
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.2.2

Open the chart page →

7,633
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
ip-address@10.2.0
10.2.2

Open the chart page →

739
homarrhelmforgeVerified publisher1.2.81 of 1See more

homarr helmforge 1.2.8

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
ip-address@10.2.0
10.2.2

Open the chart page →

435
matterbridgehelmforgeVerified publisher1.0.21 of 1See more

matterbridge helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
luligu/matterbridge:3.10.81ec50ecd0694
ip-address@10.2.0
10.2.2

Open the chart page →

895
memoshelmforgeVerified publisher2.0.01 of 2See more

memos helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.2.2

Open the chart page →

792
opencuthelmforgeVerified publisher1.1.91 of 5See more

opencut helmforge 1.1.9

1 of the 5 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.2.2

Open the chart page →

3,726
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
ip-address@10.2.0
10.2.2

Open the chart page →

2,538
pocket-idhelmforgeVerified publisher1.0.01 of 2See more

pocket-id helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.2.2

Open the chart page →

453
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.2.2
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
ip-address@10.2.0
10.2.2

Open the chart page →

3,025
twentyhelmforgeVerified publisher1.0.01 of 5See more

twenty helmforge 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.2.2

Open the chart page →

2,818
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
ip-address@10.2.0
10.2.2

Open the chart page →

8,967
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ip-address@10.2.0
10.2.2

Open the chart page →

3,436
zomboid-serverjanip81-helm-chartsVerified publisher0.1.211 of 3See more

zomboid-server janip81-helm-charts 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
ip-address@10.2.0
10.2.2

Open the chart page →

424
homebridgejespernohrVerified publisher0.2.01 of 1See more

homebridge jespernohr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.2.2

Open the chart page →

2,149
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ip-address@10.2.0
10.2.2

Open the chart page →

3,092
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.2.2

Open the chart page →

2,437
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.2.2

Open the chart page →

12,062
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.2.2

Open the chart page →

2,756
homebridgelbenicio-communityVerified publisher0.1.151 of 1See more

homebridge lbenicio-community 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.2.2

Open the chart page →

2,149
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.2.2

Open the chart page →

33,242
libredb-studiolibredb-studio-oci0.1.631 of 1See more

libredb-studio libredb-studio-oci 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
ip-address@10.2.0
10.2.2

Open the chart page →

1,222
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ip-address@10.2.0
10.2.2

Open the chart page →

1,809
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.2.2

Open the chart page →

33,242
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
ip-address@10.2.0
10.2.2
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
ip-address@10.2.0
10.2.2

Open the chart page →

2,774

Container images carrying it

116 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2
3
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.2
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
ip-address@10.2.0
10.2.2
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.2
3
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.2.2
2
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.2.2
2
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.2.2
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.2.2
2
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.2.2
2
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.2.2
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.2.2
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.2.2
2
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.2
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.2.2
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.2.2
2
requarks/wiki:2:latest68f0d1848261
ip-address@10.2.0
10.2.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.2
2
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
ip-address@10.2.0
10.2.2
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.2
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
ip-address@10.2.0
10.2.2
2
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.2.2
1
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.2.2
1
chainsafe/lodestar:latest5593f6e97912
ip-address@10.2.0
10.2.2
1
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.2.2
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.2.2
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ip-address@10.2.0
10.2.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip-address@10.2.0
10.2.2
1
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.2.2
1
diygod/rsshub:latest1d4b508b6357
ip-address@10.2.0
10.2.2
1
docmost/docmost:0.95.041c8d777cf23
ip-address@10.1.1
10.2.2
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.2.0
10.2.2
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.2.2
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
ip-address@10.2.0
10.2.2
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
ip-address@10.2.0
10.2.2
1
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.2.2
1
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.2.2
1
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.2.2
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.2.2
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.2.2
1
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.2.2
1
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.2.2
1
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.2.2
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.2.2
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.2.2
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.2.0
10.2.2
1
library/ghost:6.41.129773d6be407
ip-address@10.2.0
10.2.2
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.2.2
1
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.2.2
1
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.2.2
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.