StackRadar

CVE-2026-14457

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,769
of 17,792 indexed, latest versions
Container images
1,643
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,769 of 17,792 indexed charts deploy, on 1,643 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,190
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2442
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
OSV records
ALPINE-CVE-2026-14457DEBIAN-CVE-2026-14457UBUNTU-CVE-2026-14457
Also known as
USN-8678-1

Charts affected

1,769 by stars
ChartLatestAffected imagesRadar Score
juicefs-csi-driverwenerme0.33.01 of 5See more

juicefs-csi-driver wenerme 0.33.0

1 of the 5 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
juicedata/csi-dashboard:v0.33.05e5edb62a010
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

8,944
prometheus-nats-exporterwenerme2.23.21 of 1See more

prometheus-nats-exporter wenerme 2.23.2

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:0.20.2c623b608e148
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
vaultwenerme0.34.12 of 2See more

vault wenerme 0.34.1

2 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
hashicorp/vault:2.0.45be49781ecf7
openssl@3.5.7-r0
3.5.8-r0
hashicorp/vault-k8s:1.7.655e27b080c9b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

549
victoria-metrics-k8s-stackwenerme0.92.12 of 7See more

victoria-metrics-k8s-stack wenerme 0.92.1

2 of the 7 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
grafana/grafana:13.1.17cb8c64c4d57
openssl@3.5.7-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.8.1abb55b2165c6
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,915
wexa-studiowexa-studio1.2.04 of 15See more

wexa-studio wexa-studio 1.2.0

4 of the 15 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
openssl@3.5.0-r0
3.5.8-r0
temporalio/server:1.29.1c1e3326b2ce1
openssl@3.5.0-r0
3.5.8-r0
temporalio/ui:2.44.00b36e00aad30
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

15,056
whereaboutswhereaboutsVerified publisher0.3.01 of 1See more

whereabouts whereabouts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.4f279fd7dc112
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

618
wikiwikijs3.0.02 of 2See more

wiki wikijs 3.0.0

2 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
requarks/wiki:268f0d1848261
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

5,497
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,635
ovh-exporterwiremindVerified publisher1.2.01 of 1See more

ovh-exporter wiremind 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/wiremind/ovh-exporter:v2.3.1609f955bd977
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

209
wordpress-alpinewordpress-alpine1.5.182 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

2 of the 6 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/memcached:1.6.45dc561d52bb8a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,080
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/wordpress:latest5a93c470ae82
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,713
wicekxxczakiVerified publisher0.1.2571 of 2See more

wicek xxczaki 0.1.257

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

1,311
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

899
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

485
homerzekker6Verified publisher8.35.01 of 1See more

homer zekker6 8.35.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
b4bz/homer:v26.08.3febc8967c9f7
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
language-toolzekker6Verified publisher1.12.12 of 2See more

language-tool zekker6 1.12.1

2 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
openssl@3.5.5-r0
3.5.8-r0
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,565
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,160
zoo-project-druzoo-projectOfficialVerified publisher0.10.43 of 6See more

zoo-project-dru zoo-project 0.10.4

3 of the 6 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
curlimages/curl:8.21.07c12af72ceb3
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.4-alpine3.249a8afca54e78
openssl@3.5.7-r0
3.5.8-r0
library/rabbitmq:4.3.2-alpine835cbc6fabce
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,936

Container images carrying it

1,643 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
yooooomi/your_spotify_server:1.20.0624ea009f2ef
openssl@3.5.6-r0
3.5.8-r0
1
youssef11gaber10/flask-service:latest9c727fcfde76
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
youssef11gaber10/react-service-k8s:latestbe23f058edb6
openssl@3.5.6-r0
3.5.8-r0
1
yukimochi/activity-relay:v2.0.115798afb69216
openssl@3.5.7-r0
3.5.8-r0
1
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
openssl@3.5.5-r0
3.5.8-r0
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
openssl@3.5.1-r0
3.5.8-r0
1
zer0tonin/mikochi:1.11.009872bae1554
openssl@3.5.5-1ubuntu3.2
3.5.5-1ubuntu3.4
1
zimengxiong/excalidash-backend:0.4.271273af713c91
openssl@3.5.5-r0
3.5.8-r0
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
openssl@3.5.7-r0
3.5.8-r0
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
openssl@3.5.5-r0
3.5.8-r0
1
zimengxiong/excalidash-frontend:0.6.04ec5b20c0303
openssl@3.5.7-r0
3.5.8-r0
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
openssl@3.5.7-r0
3.5.8-r0
1
gcr.io/datadoghq/csi-driver:1.4.086c713de81d9
openssl@3.5.7-r0
3.5.8-r0
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/291-group/lan-orangutan:3.3.886b55c80eeb1
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/aardbol/opencode-server:v1.18.23-alpine7930061993f7
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/absmach/magistrala/ui-backend:latest4adf360dbf1e
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/akpw/mktxp:latest2b3ccb1c2bd9
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/akpw/mktxp:1.2.17bd6f22f7db0a
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/akpw/mktxp:1.2.20f894f2457670
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/alam00000/bentopdf-simple:2.8.5268f3e4a1aee
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/alam00000/bentopdf-simple:2.8.42bae644d2735
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/catalog-manager:v0.13.0fc336c5b9655
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/cattleset:v0.0.145554a03e448
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/cluster-presets:v0.0.128fbdd2479645
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/cluster-ui:2.4.0f527d10769ac
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/external-dns-operator:v0.4.05605f97e636d
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/appscode/inbox-agent:v0.0.66b99ee9feece
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/operator-shard-manager:v0.0.64a16c6ccecb8
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/outboxsyncer:v0.5.0150baab6115d
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/pgoutbox:v0.0.4a96e06ec5e9f
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/sidekick:v0.0.16d8d2a3c22ee7
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
openssl@3.5.4-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.