StackRadar

CVE-2026-69198

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
128
of 17,781 indexed, latest versions
Container images
116
deployed by those charts
Fix available
1 of 1
affected package

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

Carried by container images the latest versions of 128 of 17,781 indexed charts deploy, on 116 images.

Affected packageAffected versionsFixed inImages
ip-addressnpm10.1.1, 10.2.010.2.2116
OSV records
GHSA-4xrf-jv44-h6hh

Charts affected

128 by stars
ChartLatestAffected imagesRadar Score
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
ip-address@10.2.0
10.2.2

Open the chart page →

8,303
homarrmedia-servarrVerified publisher0.55.11 of 1See more

homarr media-servarr 0.55.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
ip-address@10.2.0
10.2.2

Open the chart page →

435
miot-dashboard-servermicroboxlabs0.1.11 of 1See more

miot-dashboard-server microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-dashboard-server:latest19b910920ab1
ip-address@10.2.0
10.2.2

Open the chart page →

237
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.2

Open the chart page →

10,603
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.2.2

Open the chart page →

1,759
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.2

Open the chart page →

1,038
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
ip-address@10.2.0
10.2.2

Open the chart page →

595
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.2.2
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.2.2

Open the chart page →

4,660
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.2

Open the chart page →

1,038
portalplatform-mesh-portal0.19.41 of 1See more

portal platform-mesh-portal 0.19.4

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
ip-address@10.2.0
10.2.2

Open the chart page →

301
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
ip-address@10.2.0
10.2.2

Open the chart page →

276
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.2

Open the chart page →

9,047
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ip-address@10.2.0
10.2.2

Open the chart page →

30,219
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
ip-address@10.2.0
10.2.2

Open the chart page →

3,707
rybbitrybbit-helm1.3.02 of 7See more

rybbit rybbit-helm 1.3.0

2 of the 7 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ip-address@10.2.0
10.2.2
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
ip-address@10.2.0
10.2.2

Open the chart page →

5,819
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
ip-address@10.2.0
10.2.2

Open the chart page →

387
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
ip-address@10.2.0
10.2.2

Open the chart page →

1,991
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.2

Open the chart page →

2,638
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.2

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.2

Open the chart page →

919
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
ip-address@10.2.0
10.2.2

Open the chart page →

9,556
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.2.2

Open the chart page →

5,535
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
ip-address@10.2.0
10.2.2

Open the chart page →

5,550
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
ip-address@10.2.0
10.2.2

Open the chart page →

1,787
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
ip-address@10.2.0
10.2.2

Open the chart page →

1,961
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.2.2

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-69198.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ip-address@10.2.0
10.2.2

Open the chart page →

5,459

Container images carrying it

116 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/node:ltsbe23f54a88d3
ip-address@10.2.0
10.2.2
3
localstack/localstack-pro:latest4aef81c53168
ip-address@10.2.0
10.2.2
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
ip-address@10.2.0
10.2.2
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
ip-address@10.2.0
10.2.2
3
actualbudget/actual-server:26.9.0552beab3dec8
ip-address@10.2.0
10.2.2
2
epamedp/krci-portal:0.8.0687acf641097
ip-address@10.2.0
10.2.2
2
homebridge/homebridge:latest77c685a40911
ip-address@10.2.0
10.2.2
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
ip-address@10.2.0
10.2.2
2
library/node:24.21.0-alpine3.23159fe6464903
ip-address@10.2.0
10.2.2
2
library/node:24.21.0-alpinebe80f76cf40e
ip-address@10.2.0
10.2.2
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ip-address@10.2.0
10.2.2
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ip-address@10.2.0
10.2.2
2
n8nio/n8n:2.36.714c4285bc303
ip-address@10.2.0
10.2.2
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
ip-address@10.2.0
10.2.2
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
ip-address@10.2.0
10.2.2
2
requarks/wiki:2:latest68f0d1848261
ip-address@10.2.0
10.2.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
ip-address@10.2.0
10.2.2
2
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
ip-address@10.2.0
10.2.2
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
ip-address@10.2.0
10.2.2
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
ip-address@10.2.0
10.2.2
2
archivebox/archivebox:0.7.41a5a37331091
ip-address@10.1.1
10.2.2
1
budibase/apps:3.41.344fe6feab985
ip-address@10.2.0
10.2.2
1
chainsafe/lodestar:latest5593f6e97912
ip-address@10.2.0
10.2.2
1
chocobozzz/peertube:v8.1.5052712130691
ip-address@10.2.0
10.2.2
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
ip-address@10.2.0
10.2.2
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ip-address@10.2.0
10.2.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ip-address@10.2.0
10.2.2
1
directus/directus:12.0.29c8470ea465c
ip-address@10.2.0
10.2.2
1
diygod/rsshub:latest1d4b508b6357
ip-address@10.2.0
10.2.2
1
docmost/docmost:0.95.041c8d777cf23
ip-address@10.1.1
10.2.2
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
ip-address@10.2.0
10.2.2
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
ip-address@10.2.0
10.2.2
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
ip-address@10.2.0
10.2.2
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
ip-address@10.2.0
10.2.2
1
ethpandaops/assertoor:latest1efa2fba6711
ip-address@10.2.0
10.2.2
1
foggbh/stocky:latest8b7a2e5ecf4e
ip-address@10.2.0
10.2.2
1
fosrl/pangolin:latest83a55f933b4d
ip-address@10.2.0
10.2.2
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
ip-address@10.2.0
10.2.2
1
helmforge/opencut:v0.3.0bf11156e0ab5
ip-address@10.2.0
10.2.2
1
joplin/server:latest3f7b852959aa
ip-address@10.2.0
10.2.2
1
journeyapps/powersync-service:latestbf46f66e5dcc
ip-address@10.2.0
10.2.2
1
kitware/cdash:v5.3.0d7767d9b9da4
ip-address@10.2.0
10.2.2
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
ip-address@10.2.0
10.2.2
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
ip-address@10.2.0
10.2.2
1
library/ghost:6.37.01ef2e532ca4d
ip-address@10.2.0
10.2.2
1
library/ghost:6.41.129773d6be407
ip-address@10.2.0
10.2.2
1
library/ghost:6.39.0-alpine77196da4b0df
ip-address@10.2.0
10.2.2
1
library/node:lts-alpinee67514e5d0f6
ip-address@10.2.0
10.2.2
1
library/node:latestf5d1cc40abc1
ip-address@10.2.0
10.2.2
1
lissy93/domain-locker:latestd3c95edc0a8b
ip-address@10.2.0
10.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.