StackRadar

CVE-2026-14456

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,772
of 17,803 indexed, latest versions
Container images
1,660
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,772 of 17,803 indexed charts deploy, on 1,660 images.

Affected packageAffected versionsFixed inImages
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+19 more3.5.8-r0, 3.6.3-r51,205
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+13 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2444
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
OSV records
ALPINE-CVE-2026-14456CGA-35mx-c7ph-5wqgDEBIAN-CVE-2026-14456UBUNTU-CVE-2026-14456ECHO-67da-49b3-07ec
Also known as
CGA-93ch-6vxx-3pjv, CGA-fq88-94gm-g9r9, CGA-gc6w-2x98-r76w, CGA-qchw-xc4v-23mf, CGA-x4jp-5c7q-v482, USN-8678-1

Charts affected

1,772 by stars
ChartLatestAffected imagesRadar Score
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.02 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

2 of the 4 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
openssl@3.6.1-r3
3.6.3-r5
mcpuse/inspector:latest91b25e3eb604
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,301
sibylsibyl0.2.01 of 1See more

sibyl sibyl 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,021
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,700
moksi-gitops0.16.41 of 2See more

mok si-gitops 0.16.4

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
quay.io/shivering-isles/postfix:3.11.70f40af2070c8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

664
nut-exportersi-gitops0.5.01 of 1See more

nut-exporter si-gitops 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

811
frontendsignalen4.24.01 of 1See more

frontend signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
signalen/frontend:2.27.81ab79cb7fe21
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,157
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,686
ctlogsigstoreVerified publisher0.2.681 of 4See more

ctlog sigstore 0.2.68

1 of the 4 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,749
counter-dhlsikademo0.3.02 of 3See more

counter-dhl sikademo 0.3.0

2 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ondrejsika/counter:latestd95eaeee2172
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,966
gordy-redissikademo0.1.01 of 1See more

gordy-redis sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,004
test-hello-worldsikademo0.1.01 of 1See more

test-hello-world sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,215
hello-worldsikalabs0.17.01 of 1See more

hello-world sikalabs 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,215
hello-world-examplesikalabs0.1.31 of 1See more

hello-world-example sikalabs 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
sikalabs/hello-world-server:latest5f49bf889a64
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,215
pgadminsikalabs0.1.01 of 2See more

pgadmin sikalabs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

398
vault-devsikalabs0.2.01 of 1See more

vault-dev sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
hashicorp/vault:latest5520cc26271c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

231
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,939
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,937
bitwardensinextraVerified publisher0.10.21 of 1See more

bitwarden sinextra 0.10.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,785
fluentdsinextraVerified publisher1.4.51 of 1See more

fluentd sinextra 1.4.5

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,134
headscalesinextraVerified publisher0.1.01 of 1See more

headscale sinextra 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.29.30e7f1c6e4ce6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

573
ipsecsinextraVerified publisher0.6.41 of 1See more

ipsec sinextra 0.6.4

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/ipsec:5.236f4e651d1fe
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

677
tabixsinextraVerified publisher0.2.21 of 1See more

tabix sinextra 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,250
tailscalesinextraVerified publisher0.18.11 of 2See more

tailscale sinextra 0.18.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/tailscale:1.102.3d91287e83d1a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,082
mosquittosintef-mosquitto-helm-chart0.1.11 of 1See more

mosquitto sintef-mosquitto-helm-chart 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.22212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
yopasssky-sailVerified publisher1.3.11 of 2See more

yopass sky-sail 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/memcached:1.6.409ae868852d0b
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,065
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

4,007
multicloudsmo-helm-chart6.0.01 of 14See more

multicloud smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/rabbitmq:alpine3486d98205df
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

9,577
smtpsmtpVerified publisher1.3.31 of 1See more

smtp smtp 1.3.3

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,431
avalanchesnowplow-devopsVerified publisher0.12.11 of 6See more

avalanche snowplow-devops 0.12.1

1 of the 6 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,330
axonhubsnubisks0.1.02 of 3See more

axonhub snubisks 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
openssl@3.5.7-r0
3.5.8-r0
looplj/axonhub:latest2c71eeaef295
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

684
deeplxsnubisks0.1.01 of 1See more

deeplx snubisks 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
missuo/deeplx:v1.2.232e492587678
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

480
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
openssl@3.4.1-r2
3.6.3-r5

Open the chart page →

8,166
ingress-nginxsoftonic4.15.11 of 2See more

ingress-nginx softonic 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,541
kube-prometheus-stacksoftonic81.5.12 of 6See more

kube-prometheus-stack softonic 81.5.1

2 of the 6 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
grafana/grafana:12.3.2ba93c9d192e5
openssl@3.5.4-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

5,017
bootzookasoftwaremillVerified publisher0.2.11 of 2See more

bootzooka softwaremill 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
softwaremill/bootzooka:latest845b5e8f8056
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.4

Open the chart page →

3,117
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

592
solidinvoicesolidinvoiceVerified publisher3.0.11 of 1See more

solidinvoice solidinvoice 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
solidinvoice/solidinvoice:3.0.1ae7c0e155cb5
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
redissomaz94Verified publisher0.1.21 of 1See more

redis somaz94 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/redis:8.2-alpine30abb90e62f1
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

180
sqs-to-snssqs-to-sns2.0.151 of 1See more

sqs-to-sns sqs-to-sns 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
udhos/sqs-to-sns:2.0.15cf7979da82e1
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

950
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,529
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,597
servicexssl-hep1.8.511 of 16See more

servicex ssl-hep 1.8.5

11 of the 16 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/python:3.1070c9cc675605
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ncsa/checks:main0b738bbc8d70
openssl@3.5.1-1
3.5.7-1~deb13u2
sslhep/servicex_app:v1.8.51d12f943cec5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex-did-finder-atlasopenmagic:v1.8.554aaf1721d03
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex-did-finder-cernopendata:v1.8.52cb88ceab5bb
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

68,698
hazelcaststakaterVerified publisher1.0.21 of 1See more

hazelcast stakater 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
hazelcast/hazelcast:latestf086bf0ecb23
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,696
my-appstakefish0.1.01 of 3See more

my-app stakefish 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

280
multus-cnistartechnicaVerified publisher0.1.41 of 1See more

multus-cni startechnica 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:latest-thickb2136983532b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,055
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,354
dotstatsuitestatcan0.2.81 of 6See more

dotstatsuite statcan 0.2.8

1 of the 6 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
siscc/dotstatsuite-dbup:master432e55811520
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,878
fdi-dotstatsuitestatcan0.3.51 of 3See more

fdi-dotstatsuite statcan 0.3.5

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
siscc/sdmxri-nsi-maapi:master6cf1145566f0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

566
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

6,068
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

921

Container images carrying it

1,660 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.8-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.8-r0
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.