StackRadar

CVE-2025-9230

High

Advisory

Published 30 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,736
of 17,803 indexed, latest versions
Container images
3,257
deployed by those charts
Fix available
6 of 7
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,736 of 17,803 indexed charts deploy, on 3,257 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+98 more1.0.1f-1ubuntu2.27+esm11, 1.0.2g-1ubuntu4.20+esm13, 1.1.1-1ubuntu2.1~18.04.23+esm6, 1.1.1f-1ubuntu2.24+esm1+5 more1,963
opensslapk3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+38 more3.0.19-r0, 3.1.8-r1, 3.3.5-r0, 3.5.4-r0969
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm215
opensslrpm1:1.0.2k-16.el7_6.1, 1:1.0.2k-19.el7, 1:1.0.2k-21.el7_9, 1:1.0.2k-22.el7_9+29 more1:1.0.2k-26.el7_9.1, 1:1.1.1k-14.el8_10, 1:3.2.2-7.el9_6.1, 1:3.5.1-4.el9_7322
openssl-3rpm3.2.3-150700.5.18.13.2.3-150700.5.21.13
openssl-1_1rpm1.1.1w-150700.11.3.11.1.1w-150700.11.6.11
OSV records
ALPINE-CVE-2025-9230CGA-c4v2-6rpm-vq95DEBIAN-CVE-2025-9230UBUNTU-CVE-2025-9230RHSA-2025:21174RHSA-2025:21255RHSA-2026:0337RHSA-2026:1720RLSA-2025:21255RLSA-2026:0337DLA-4321-1SUSE-SU-2025:03546-1SUSE-SU-2025:03635-1
Also known as
CGA-qm4c-c7mv-j233, RHSA-2025:21562, RHSA-2026:0602, RHSA-2026:0714, RHSA-2026:0794, RHSA-2026:0887, RHSA-2026:1475, USN-7786-1

Charts affected

2,736 by stars
ChartLatestAffected imagesRadar Score
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
openssl@3.0.15-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

5,150
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
openssl@3.0.13-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

4,548
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
openssl@1:1.1.1c-2.el8_1.1
1:1.1.1k-14.el8_10

Open the chart page →

9,855
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.6

Open the chart page →

4,087
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
openssl@1:1.1.1c-15.el8
1:1.1.1k-14.el8_10

Open the chart page →

12,847
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.20

Open the chart page →

5,405
ingress-nginxjfrog4.5.21 of 2See more

ingress-nginx jfrog 4.5.2

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
openssl@3.0.8-r0
3.0.19-r0

Open the chart page →

3,798
vaultjfrog0.25.01 of 2See more

vault jfrog 0.25.0

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.2.14500e988b7ce
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

3,980
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm6

Open the chart page →

7,896
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.6

Open the chart page →

6,657
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.6

Open the chart page →

6,638
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

917
xxl-job-adminjoelee2012Verified publisher1.1.01 of 2See more

xxl-job-admin joelee2012 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
xuxueli/xxl-job-admin:2.4.0640093c35fd6
openssl@1.1.1n-0+deb11u1
1.1.1w-0+deb11u4

Open the chart page →

3,118
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
openssl@1.1.1k-1+deb11u1
1.1.1w-0+deb11u4

Open the chart page →

3,842
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
openssl@1.1.1n-0+deb11u3
1.1.1w-0+deb11u4

Open the chart page →

2,318
image-storage-servicejtektVerified publisher0.4.34 of 4See more

image-storage-service jtekt 0.4.3

4 of the 4 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
openssl@1.1.1n-0+deb11u5
1.1.1w-0+deb11u4
library/kong:3.6a42d2b4503e7
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.20
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssl@3.0.14-1~deb12u2
3.0.17-1~deb12u3
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
openssl@3.0.14-1~deb12u2
3.0.17-1~deb12u3

Open the chart page →

22,748
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
openssl@1.1.1n-0+deb11u4
1.1.1w-0+deb11u4

Open the chart page →

2,234
shinsei-managerjtektVerified publisher0.2.06 of 8See more

shinsei-manager jtekt 0.2.0

6 of the 8 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
library/neo4j:5.20.052d3dec8d455
openssl@1.1.1w-0+deb11u1
1.1.1w-0+deb11u4
moreillon/api-proxy:latestd7d4a5463525
openssl@3.0.16-1~deb12u1
3.0.17-1~deb12u3
moreillon/user-manager:v5.0.2e1c9bfab5c16
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3
moreillon/user-manager-front:v5.0.3b067dbbbb6af
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3

Open the chart page →

63,932
time-series-storagejtektVerified publisher0.1.102 of 2See more

time-series-storage jtekt 0.1.10

2 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
openssl@1.1.1n-0+deb11u4
1.1.1w-0+deb11u4
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3

Open the chart page →

16,710
k10appk10app0.2.14 of 11See more

k10app k10app 0.2.1

4 of the 11 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
openssl@3.0.7-r0
3.0.19-r0
ghcr.io/k10app/frontend:latest066b5ac6b119
openssl@1.1.1n-0+deb11u3
1.1.1w-0+deb11u4
ghcr.io/k10app/order:lateste1017d0dbd78
openssl@3.0.7-r0
3.0.19-r0
ghcr.io/k10app/staticcache:lateste77805689a8e
openssl@1.1.1n-0+deb11u3
1.1.1w-0+deb11u4

Open the chart page →

10,607
bitcoin-stackk8s-chartsVerified publisher1.0.11 of 1See more

bitcoin-stack k8s-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
blockstream/bitcoind:27.29472492530e3
openssl@3.0.15-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

2,462
jellyfink8s-chartsVerified publisher0.2.41 of 1See more

jellyfin k8s-charts 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.696b09723b22f
openssl@3.0.15-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

4,164
nostr-rs-relayk8s-chartsVerified publisher1.0.11 of 1See more

nostr-rs-relay k8s-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
scsibug/nostr-rs-relay:0.9.003f54bfbffff
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3

Open the chart page →

3,397
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.20

Open the chart page →

57,344
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
openssl@3.3.4-r0
3.3.5-r0

Open the chart page →

1,904
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.6

Open the chart page →

62,809
k8sforjavak8sforjava0.1.01 of 1See more

k8sforjava k8sforjava 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
vincentgwzhang/k8sforjava:latesta9139f2cd98f
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

1,466
interplexk8sgptVerified publisher1.1.01 of 1See more

interplex k8sgpt 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/interplex-ai/interplex:v1.1.041b0dd0d55b2
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

746
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

2,752
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
openssl@1.1.1n-0+deb11u3
1.1.1w-0+deb11u4

Open the chart page →

2,371
readarrk8s-home-lab-repo7.2.11 of 1See more

readarr k8s-home-lab-repo 7.2.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/home-operations/readarr:0.4.188f7551205fbd
openssl@3.5.0-r0
3.5.4-r0

Open the chart page →

1,099
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
nodejs@16.14.2-deb-1nodesource1
openssl@3.0.2-0ubuntu1.9
no fix listed
3.0.2-0ubuntu1.20

Open the chart page →

9,865
zurgk8s-home-lab-repo1.2.11 of 1See more

zurg k8s-home-lab-repo 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
openssl@3.3.1-r0
3.3.5-r0

Open the chart page →

1,733
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

2,443
k8s-mutating-webhookk8s-mutating-webhook0.3.02 of 2See more

k8s-mutating-webhook k8s-mutating-webhook 0.3.0

2 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
openssl@3.3.2-r0
3.3.5-r0
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
openssl@3.1.4-r5
3.1.8-r1

Open the chart page →

2,012
librephotosk8sonlabVerified publisher1.1.62 of 7See more

librephotos k8sonlab 1.1.6

2 of the 7 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
openssl@3.0.16-1~deb12u1
3.0.17-1~deb12u3
bitnamilegacy/redis:latest5927ff3702df
openssl@3.0.16-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

14,969
netio-exporterk8sonlabVerified publisher0.1.101 of 1See more

netio-exporter k8sonlab 0.1.10

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
tomsajan/netio-exporter:0.0.5fb61907707b8
openssl@3.1.4-r6
3.1.8-r1

Open the chart page →

728
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm1

Open the chart page →

7,445
k8s-ssh-bastionk8s-ssh-bastion0.5.41 of 1See more

k8s-ssh-bastion k8s-ssh-bastion 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.6

Open the chart page →

3,342
k8s-validating-webhookk8s-validating-webhook0.4.02 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

2 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
openssl@3.3.2-r0
3.3.5-r0
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
openssl@3.1.4-r5
3.1.8-r1

Open the chart page →

2,012
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
openssl@3.3.2-r0
3.3.5-r0

Open the chart page →

2,169
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
openssl@3.0.2-0ubuntu1.20
no fix listed

Open the chart page →

3,631
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm1

Open the chart page →

7,369
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,634
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.5-r0

Open the chart page →

1,433
kanrikanri0.1.01 of 1See more

kanri kanri 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/hypolia/kanri:0.1.2-rc4fa7d5cc7fb7d
openssl@3.0.15-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

2,126
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm1

Open the chart page →

79,018
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
openssl@3.0.11-1~deb12u2
3.0.17-1~deb12u3

Open the chart page →

8,915
kcmkcm1.12.01 of 12See more

kcm kcm 1.12.0

1 of the 12 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
openssl@3.0.2-0ubuntu1.25
no fix listed

Open the chart page →

3,318
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2025-9230.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
openssl@3.0.16-1~deb12u1
3.0.17-1~deb12u3

Open the chart page →

5,282

Container images carrying it

3,257 by charts deploying them

A fixed version is listed for 6 of the 7 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
openssl@1:3.2.2-6.el9_5.1
1:3.5.1-4.el9_7
1
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
openssl@3.4.1-r2
3.5.4-r0
1
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
openssl@3.4.1-r0
3.5.4-r0
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
openssl@1:3.2.2-6.el9_5.1
1:3.5.1-4.el9_7
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
openssl@1:3.2.2-6.el9_5
1:3.5.1-4.el9_7
1
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
openssl@3.3.2-r0
3.5.4-r0
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
openssl@3.0.14-1~deb12u2
3.0.17-1~deb12u3
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
openssl@1.1.1n-0+deb11u3
1.1.1w-0+deb11u4
1
gcr.io/ml-pipeline/cache-server:2.3.0293941ee4f65
openssl@3.1.6-r2
3.1.8-r1
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm13
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm1
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
openssl@3.0.14-1~deb12u2
3.0.17-1~deb12u3
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
openssl@1.1.1n-0+deb11u3
1.1.1w-0+deb11u4
1
gcr.io/ml-pipeline/persistenceagent:2.3.0109ac1b38c41
openssl@3.1.6-r2
3.1.8-r1
1
gcr.io/ml-pipeline/scheduledworkflow:2.3.0f7e67e0bc071
openssl@3.1.6-r2
3.1.8-r1
1
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
openssl@3.3.1-r3
3.3.5-r0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
3.0.17-1~deb12u3
1
gcr.io/projectsigstore/cosigned784518ff3ee7
openssl@1.1.1n-0+deb11u1
1.1.1w-0+deb11u4
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
openssl@1.1.1n-0+deb11u1
1.1.1w-0+deb11u4
1
gcr.io/prysmaticlabs/prysm/beacon-chain:stable31239807cbbd
openssl@1.1.1w-0+deb11u1
1.1.1w-0+deb11u4
1
gcr.io/prysmaticlabs/prysm/beacon-chain:v6.1.28ef452191a3a
openssl@1.1.1w-0+deb11u1
1.1.1w-0+deb11u4
1
gcr.io/prysmaticlabs/prysm/validator:v6.0.1a7d06fcfe91f
openssl@1.1.1w-0+deb11u1
1.1.1w-0+deb11u4
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
openssl@3.0.15-1~deb12u1
3.0.17-1~deb12u3
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.4-r0
1
ghcr.io/0xemma/reddark:main2a115e991894
openssl@1.1.1n-0+deb11u4
1.1.1w-0+deb11u4
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm6
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
openssl@1:3.2.2-6.el9_5.1
1:3.2.2-7.el9_6.1
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.6
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.6
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
openssl@1.1.1w-0+deb11u3
1.1.1w-0+deb11u4
1
ghcr.io/ajnart/homarr:lateste103abadfb52
openssl@1.1.1n-0+deb11u4
1.1.1w-0+deb11u4
1
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
openssl@3.0.2-0ubuntu1.25
no fix listed
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.6
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
openssl@1.1.1w-0+deb11u2
1.1.1w-0+deb11u4
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
openssl@3.0.14-1~deb12u2
3.0.17-1~deb12u3
1
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
openssl@3.3.2-r0
3.3.5-r0
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.20
1
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
openssl@3.1.4-r2
3.1.8-r1
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
openssl@3.3.2-r4
3.3.5-r0
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
openssl@3.3.1-r1
3.3.5-r0
1
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.20
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
openssl@3.3.3-r0
3.3.5-r0
1
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
openssl@3.1.4-r5
3.1.8-r1
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
openssl@3.3.2-r1
3.3.5-r0
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.20
1
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
openssl@1.1.1k-1+deb11u2
1.1.1w-0+deb11u4
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.