StackRadar

CVE-2026-14457

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,760
of 17,797 indexed, latest versions
Container images
1,625
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,760 of 17,797 indexed charts deploy, on 1,625 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,173
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2441
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
OSV records
ALPINE-CVE-2026-14457DEBIAN-CVE-2026-14457UBUNTU-CVE-2026-14457
Also known as
USN-8678-1

Charts affected

1,760 by stars
ChartLatestAffected imagesRadar Score
prometheus-conntrack-stats-exporterprometheus-communityOfficialVerified publisher0.5.391 of 1See more

prometheus-conntrack-stats-exporter prometheus-community 0.5.39

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
jwkohnen/conntrack-stats-exporter:v0.4.471303223183bb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

205
prometheus-pingdom-exporterprometheus-communityVerified publisher3.4.41 of 1See more

prometheus-pingdom-exporter prometheus-community 3.4.4

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/pingdom-exporter:v0.5.73e52df096943
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

205
github-exporterpromhippieVerified publisher20.0.01 of 1See more

github-exporter promhippie 20.0.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/github-exporter:19.0.0d3f23225fde9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
hetzner-exporterpromhippieVerified publisher2.15.11 of 1See more

hetzner-exporter promhippie 2.15.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/hetzner-exporter:2.15.1fef37ffbd2b6
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
jenkins-exporterpromhippieVerified publisher2.14.11 of 1See more

jenkins-exporter promhippie 2.14.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/jenkins-exporter:2.14.1b85f303da376
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
prometheus-hcloud-sdpromhippieVerified publisher3.27.11 of 1See more

prometheus-hcloud-sd promhippie 3.27.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/prometheus-hcloud-sd:2.27.17353de739311
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
prometheus-hetzner-sdpromhippieVerified publisher3.19.01 of 1See more

prometheus-hetzner-sd promhippie 3.19.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/prometheus-hetzner-sd:2.19.085db9f61eba1
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
prometheus-scw-sdpromhippieVerified publisher2.18.11 of 1See more

prometheus-scw-sd promhippie 2.18.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/prometheus-scw-sd:2.18.1ad53a2942e01
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
prometheus-vcd-sdpromhippieVerified publisher3.12.11 of 1See more

prometheus-vcd-sd promhippie 3.12.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/prometheus-vcd-sd:2.12.175b05355d439
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
scw-exporterpromhippieVerified publisher3.15.11 of 1See more

scw-exporter promhippie 3.15.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
quay.io/promhippie/scw-exporter:2.15.11952125f8423
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
prompt-dbprompt-dbVerified publisher1.0.72 of 3See more

prompt-db prompt-db 1.0.7

2 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,366
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/postgres:18-alpined3e1620b530c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,655
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,856
kaiman-webhooks-proxypwVerified publisher1.1.11 of 1See more

kaiman-webhooks-proxy pw 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
tinyops/kwp:1.2.0e009ee400d78
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
shortlypwVerified publisher1.1.72 of 2See more

shortly pw 1.1.7

2 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/nginx:1.30.0-alpine3.23-slim2fb5d772cea6
openssl@3.5.6-r0
3.5.8-r0
tinyops/shortly:1.6.0483915cb2d21
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

500
loki-stackpyalive-cdmswebappVerified publisher2.6.51 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

1 of the 4 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

6,556
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

14,624
qantas-apiqantas-helm0.1.01 of 3See more

qantas-api qantas-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,667
open-terminalqaoruVerified publisher0.2.41 of 1See more

open-terminal qaoru 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/open-webui/open-terminal:0.13.0-slimdec44673c865
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,056
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,408
couchdbquench-couchdbVerified publisher0.0.121 of 2See more

couchdb quench-couchdb 0.0.12

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
curlimages/curl:8.21.07c12af72ceb3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

188
gohoarderraczylo-comVerified publisher0.1.1741 of 4See more

gohoarder raczylo-com 0.1.174

1 of the 4 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/lukaszraczylo/gohoarder-migrate:0.1.174ed6053b62bb2
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
headlampradar-baseVerified publisher1.0.01 of 1See more

headlamp radar-base 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

622
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.4

Open the chart page →

3,232
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

2,186
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,508
ratecapratecapVerified publisher0.1.22 of 3See more

ratecap ratecap 0.1.2

2 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/sairam0424/ratecap-core:latest2f6c7157fa8e
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/sairam0424/ratecap-sidecar:lateste7feca7ac7cc
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

298
mihomos-clusterre8ch-mihomos-clusterVerified publisher0.1.11 of 3See more

mihomos-cluster re8ch-mihomos-cluster 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
metacubex/mihomo:v1.19.29e1d7dadaa936
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

582
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,861
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,792
etherpadredhat-cop0.0.81 of 1See more

etherpad redhat-cop 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
etherpad/etherpad:latest6020e7b57f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

896
redis-cartredis-chart0.1.01 of 1See more

redis-cart redis-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

168
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,296
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,040
redminerestic-pvc-backupVerified publisher0.2.61 of 1See more

redmine restic-pvc-backup 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/redmine:6.1.3-trixief474a901faec
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,284
restic-pvc-backuprestic-pvc-backupVerified publisher0.2.12 of 2See more

restic-pvc-backup restic-pvc-backup 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ngosang/restic-exporter:2.1.2a8f9cfa30162
openssl@3.5.7-r0
3.5.8-r0
restic/restic:0.19.1136600b6ff68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

954
restinthemiddlerestinthemiddleVerified publisher2.0.31 of 1See more

restinthemiddle restinthemiddle 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
jdschulze/restinthemiddle:v2.3.13fde2dfbcacc2
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
delugeretsamedocVerified publisher26.9.01 of 1See more

deluge retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
linuxserver/deluge:2.2.09505c64720af
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

775
rhiorhio0.3.41 of 1See more

rhio rhio 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/hiro-microdatacenters-bv/rhio:0.3.4-3e6bec1ea7f4c4287646
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
rhio-operatorrhio0.3.41 of 1See more

rhio-operator rhio 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/hiro-microdatacenters-bv/rhio:0.3.4-3e6bec1ea7f4c4287646
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

278
libretranslaterivals-spaceVerified publisher1.0.01 of 2See more

libretranslate rivals-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
harvester-cloud-providerrke2-charts0.2.15001 of 2See more

harvester-cloud-provider rke2-charts 0.2.1500

1 of the 2 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
rancher/mirrored-kube-vip-kube-vip-iptables:v1.2.389c3f898ac5a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

452
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,622
networking-toolboxrm3lVerified publisher0.1.01 of 1See more

networking-toolbox rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
lissy93/networking-toolbox:latest700862839553
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

824
wg-easyrm3lVerified publisher0.2.01 of 1See more

wg-easy rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,160
matrix-stackrock8sVerified publisher0.8.12 of 7See more

matrix-stack rock8s 0.8.1

2 of the 7 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/haproxy:3.1-alpine475863a372c9
openssl@3.5.6-r0
3.5.8-r0
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

9,328
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
library/memcached:alpinec29847751abb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

6,202
monitoringrocketchat-server0.0.172 of 9See more

monitoring rocketchat-server 0.0.17

2 of the 9 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
openssl@3.5.1-r0
3.5.8-r0
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

6,887
jaegerromanow-helm-chartsVerified publisher1.7.31 of 1See more

jaeger romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-14457.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.9.0e128b9adbb29
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,605

Container images carrying it

1,625 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/promhippie/prometheus-vcd-sd:2.12.175b05355d439
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/promhippie/scw-exporter:2.15.11952125f8423
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.8-r0
1
quay.io/seamware/did-helper:0.6.0799c5f566952
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
openssl@3.5.6-r0
3.5.8-r0
1
quay.io/shesselink81/anna-nginx:v1.31.1120c19fa8a918
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/shesselink81/hesselinkme-nginx:v1.31.114f43beb13fc2
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/shivering-isles/postfix:3.11.70f40af2070c8
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.8-r0
1
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
openssl@3.5.7-r0
3.5.8-r0
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/gitlab-ci-utils/curl-jq:latestb564745b6cb0
openssl@3.5.7-r1
3.5.8-r0
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.8-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.8-r0
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.