StackRadar

CVE-2019-3856

High

Advisory

Published 25 Mar 2019In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.061
93rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
libssh2apk1.8.0-r41.8.1-r04
libssh2deb1.5.0-2ubuntu0.11.5.0-2ubuntu0.1+esm11
OSV records
ALPINE-CVE-2019-3856UBUNTU-CVE-2019-3856
Also known as
USN-5308-1

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
atlantiscloudnativeapp3.3.11 of 1See more

atlantis cloudnativeapp 3.3.1

1 of the 1 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.7.168fa470d1416
libssh2@1.8.0-r4
1.8.1-r0

Open the chart page →

1,512
k8s-spot-termination-handlercloudnativeapp1.2.11 of 1See more

k8s-spot-termination-handler cloudnativeapp 1.2.1

1 of the 1 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
libssh2@1.8.0-r4
1.8.1-r0

Open the chart page →

2,095
orientdbcloudnativeapp0.1.21 of 2See more

orientdb cloudnativeapp 0.1.2

1 of the 2 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
library/orientdb:3.0.1318a6c004398f
libssh2@1.8.0-r4
1.8.1-r0

Open the chart page →

1,822
ser2sockgeek-cookbookVerified publisher5.4.21 of 1See more

ser2sock geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
tenstartups/ser2sock:latest379d9338c720
libssh2@1.8.0-r4
1.8.1-r0

Open the chart page →

1,596
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2019-3856.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1

Open the chart page →

29,124

Container images carrying it

5 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libssh2@1.5.0-2ubuntu0.1
1.5.0-2ubuntu0.1+esm1
3
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
libssh2@1.8.0-r4
1.8.1-r0
1
library/orientdb:3.0.1318a6c004398f
libssh2@1.8.0-r4
1.8.1-r0
1
runatlantis/atlantis:v0.7.168fa470d1416
libssh2@1.8.0-r4
1.8.1-r0
1
tenstartups/ser2sock:latest379d9338c720
libssh2@1.8.0-r4
1.8.1-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.