StackRadar

CVE-2026-14456

High

Advisory

Published 13 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,772
of 17,803 indexed, latest versions
Container images
1,660
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,772 of 17,803 indexed charts deploy, on 1,660 images.

Affected packageAffected versionsFixed inImages
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+19 more3.5.8-r0, 3.6.3-r51,205
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+13 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2444
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
OSV records
ALPINE-CVE-2026-14456CGA-35mx-c7ph-5wqgDEBIAN-CVE-2026-14456UBUNTU-CVE-2026-14456ECHO-67da-49b3-07ec
Also known as
CGA-93ch-6vxx-3pjv, CGA-fq88-94gm-g9r9, CGA-gc6w-2x98-r76w, CGA-qchw-xc4v-23mf, CGA-x4jp-5c7q-v482, USN-8678-1

Charts affected

1,772 by stars
ChartLatestAffected imagesRadar Score
anna-nginxstatic-nginx1.31.111 of 2See more

anna-nginx static-nginx 1.31.11

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
quay.io/shesselink81/anna-nginx:v1.31.1120c19fa8a918
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

531
hesselinkme-nginxstatic-nginx1.31.111 of 2See more

hesselinkme-nginx static-nginx 1.31.11

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
quay.io/shesselink81/hesselinkme-nginx:v1.31.114f43beb13fc2
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

531
node-configstevehipwellVerified publisher0.7.01 of 2See more

node-config stevehipwell 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,526
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

689
stunner-prometheusstunner0.2.11 of 4See more

stunner-prometheus stunner 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,064
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/subshell/group-challenge:0.14.19a64f1db04da
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,617
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,058
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,851
mybbsudermanjr0.1.01 of 3See more

mybb sudermanjr 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
mybb/mybb:1.8f2a54bce31c5
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,151
stresssudermanjr0.2.01 of 1See more

stress sudermanjr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

753
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,443
prowlarrsudo-kraken-prowlarrVerified publisher3.2.11 of 1See more

prowlarr sudo-kraken-prowlarr 3.2.1

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/home-operations/prowlarr:2.3.01a8a4b11972b
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

878
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,130
svc-lb-muxsvc-lb-mux0.1.31 of 1See more

svc-lb-mux svc-lb-mux 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,472
sveltos-dashboardsveltosVerified publisher1.15.11 of 2See more

sveltos-dashboard sveltos 1.15.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
projectsveltos/dashboard:v1.15.01380c9314dd4
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

160
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,745
of-dlswuuper-githubVerified publisher0.1.21 of 2See more

of-dl swuuper-github 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/alpine:3.2214358309a308
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,409
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
mikefarah/yq:4cfc4eee65859
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

8,291
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,295
minecraftsyntaxerror404Verified publisher1.2.232 of 2See more

minecraft syntaxerror404 1.2.23

2 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
alpine/curl:8.22.0b9c839d47281
openssl@3.5.7-r0
3.5.8-r0
library/eclipse-temurin:25.0.3_9-jre-alpine-3.2328db6fdf60e3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

461
teamspeaksyntaxerror404Verified publisher1.0.101 of 1See more

teamspeak syntaxerror404 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/teamspeak:3.13.815acbc64c92f
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

450
vaultwardensyself1.0.01 of 1See more

vaultwarden syself 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
vaultwarden/server:latest094b5689ed81
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,785
tarkatarkaOfficialVerified publisher0.4.12 of 4See more

tarka tarka 0.4.1

2 of the 4 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
openssl@3.6.2-r2
3.6.3-r5
ghcr.io/tarkyaio/tarka-ui:0.4.1b2dfabe13cfe
openssl@3.6.2-r2
3.6.3-r5

Open the chart page →

1,577
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,111
giropops-senhas-prdtechpreta0.1.01 of 2See more

giropops-senhas-prd techpreta 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
nataliagranato/redis:v1.0.052bd9b79a8f2
openssl@3.3.1-r4
3.6.3-r5

Open the chart page →

913
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,039
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

513
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

4,228
pingmetektonops0.1.21 of 1See more

pingme tektonops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
khaliq/pingme:v0.2.749f96888d2ab
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,254
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,143
tensorzerotensorzero2026.6.02 of 2See more

tensorzero tensorzero 2026.6.0

2 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
tensorzero/gateway:2026.6.0c939db4f27e4
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
tensorzero/ui:2026.6.0f2563d54724e
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,071
supabaseteochenglim0.1.23 of 13See more

supabase teochenglim 0.1.2

3 of the 13 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
supabase/realtime:latestd3aa0c86c7b3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
supabase/storage-api:latestf6c42a04163d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

9,862
terminusterminusVerified publisher1.1.01 of 1See more

terminus terminus 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/terminus-io/enforcer:v1.1.0f21b905610d6
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

640
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,860
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

20,436
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,410
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,668
openmeteo-exporterth-chartsVerified publisher0.1.61 of 1See more

openmeteo-exporter th-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
thelande/openmeteo_exporter:v1.0.77e9072ace15f
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,381
prusa-exporterth-chartsVerified publisher0.3.01 of 1See more

prusa-exporter th-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
pubeldev/prusa_exporter:2.0.01091665a020a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

907
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.8-r0
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,503
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,821
todolist-charttodolist-chart0.1.74 of 10See more

todolist-chart todolist-chart 0.1.7

4 of the 10 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
openssl@3.5.1-1
3.5.7-1~deb13u2
erenozcan17/go_backend:v4.250b4f23422b6
openssl@3.5.1-r0
3.5.8-r0
erenozcan17/react_frontend:v4.56e1b14973f9b
openssl@3.5.1-r0
3.5.8-r0
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,076
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,215
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,113
token-servertoken-server1.0.91 of 1See more

token-server token-server 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
udhos/token-server:1.0.9728013f2fac1
openssl@3.5.2-r0
3.5.8-r0

Open the chart page →

1,246
hub-managertraefikVerified publisher1.0.01 of 1See more

hub-manager traefik 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

649
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,669
apptreenityVerified publisher0.1.532 of 2See more

app treenity 0.1.53

2 of the 2 container images this version deploys carry CVE-2026-14456.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,854

Container images carrying it

1,660 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.8-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.8-r0
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.