StackRadar

CVE-2026-18798

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,760
of 17,797 indexed, latest versions
Container images
1,625
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,760 of 17,797 indexed charts deploy, on 1,625 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,173
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2441
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
OSV records
ALPINE-CVE-2026-18798DEBIAN-CVE-2026-18798UBUNTU-CVE-2026-18798
Also known as
USN-8678-1

Charts affected

1,760 by stars
ChartLatestAffected imagesRadar Score
mosquittoschichtelVerified publisher0.3.41 of 1See more

mosquitto schichtel 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.22212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
nvme-exporterschichtelVerified publisher0.1.61 of 1See more

nvme-exporter schichtel 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,071
pev2schichtelVerified publisher0.3.01 of 1See more

pev2 schichtel 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
dalibo/explain.dalibo.com:2.20.12a0b749c2f7f
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,179
s3-backupschichtelVerified publisher0.10.01 of 1See more

s3-backup schichtel 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,384
teamspeak3schichtelVerified publisher1.0.21 of 1See more

teamspeak3 schichtel 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/teamspeak:3.13.74d3fa1c0db9a
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

774
vaultwardenschichtelVerified publisher0.9.21 of 1See more

vaultwarden schichtel 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,766
wordpressschichtelVerified publisher0.10.102 of 2See more

wordpress schichtel 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/wordpress:6.9.4-fpmad4a8bae2eb4
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
nginxinc/nginx-unprivileged:1.29.5c5b989ebc150
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

8,316
zncschichtelVerified publisher0.3.11 of 1See more

znc schichtel 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/znc:1.10.1c731c6a9b8b6
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

750
cinnyappschoenwald1.0.111 of 1See more

cinnyapp schoenwald 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/cinnyapp/cinny:v4.12.6a7805a8a60ff
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

800
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

389
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,130
minifluxschoenwald0.1.61 of 1See more

miniflux schoenwald 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
miniflux/miniflux:2.3.349d7b6098761
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

234
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,798
ddclientschoolguys-helmcharts0.2.11 of 1See more

ddclient schoolguys-helmcharts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
linuxserver/ddclient:4.0.06468911d00b1
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

360
eclipse-mqttschoolguys-helmcharts0.1.21 of 1See more

eclipse-mqtt schoolguys-helmcharts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.22212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
hetzner-ddnsschoolguys-helmcharts0.1.21 of 1See more

hetzner-ddns schoolguys-helmcharts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
filiparag/hetzner_ddns:1.0.15a9cbae7997c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

845
jellyfinschoolguys-helmcharts0.4.21 of 1See more

jellyfin schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.81694ff069f0c
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,035
mikrotik-exporterschoolguys-helmcharts0.2.41 of 1See more

mikrotik-exporter schoolguys-helmcharts 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/akpw/mktxp:1.2.17bd6f22f7db0a
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

583
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.4

Open the chart page →

10,464
restic-serverschoolguys-helmcharts0.3.11 of 1See more

restic-server schoolguys-helmcharts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
restic/rest-server:0.14.0d2aff06f47eb
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

2,260
vaultwardenschoolguys-helmcharts0.3.91 of 1See more

vaultwarden schoolguys-helmcharts 0.3.9

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1-alpineb094afed4ed5
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

290
sealed-secrets-websealed-secrets-web-ociVerified publisher3.3.21 of 1See more

sealed-secrets-web sealed-secrets-web-oci 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/bakito/sealed-secrets-web:v3.3.2cb4d892c61c3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,294
seawise-dashboardseawiseVerified publisher1.7.11 of 1See more

seawise-dashboard seawise 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
shwcloud/seawise-backup:v1.7.1a97479a54df4
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,109
persistence-elasticsecurecodebox-persistence-elastic5.7.01 of 1See more

persistence-elastic securecodebox-persistence-elastic 5.7.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
securecodebox/persistence-elastic-dashboard-importer:5.7.0afcefbd56d61
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

879
trivysecurecodebox-trivy5.9.01 of 1See more

trivy securecodebox-trivy 5.9.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
aquasec/trivy:0.74.062b1e65e8869
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

439
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,993
postgresself-hosters-by-nightVerified publisher0.14.31 of 1See more

postgres self-hosters-by-night 0.14.3

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:18.11090bc3a8ccf
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,415
rdpgwsergiotocaliniVerified publisher1.0.01 of 1See more

rdpgw sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
bolkedebruin/rdpgw:masterc0dc0589373a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

687
service-exampleservice-example-10.1.01 of 7See more

service-example service-example-1 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

9,109
serviceexampleserviceexample-chart0.3.01 of 4See more

serviceexample serviceexample-chart 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,042
serviceexampleservice-example-helm-chart0.1.01 of 4See more

serviceexample service-example-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,309
service-exampleservice-example-jt0.1.13 of 9See more

service-example service-example-jt 0.1.1

3 of the 9 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/nats:2.12.2-alpine2d5fce3229ae
openssl@3.5.4-r0
3.5.8-r0
natsio/nats-box:0.19.28031d190c7ee
openssl@3.5.4-r0
3.5.8-r0
natsio/nats-server-config-reloader:0.20.147094fcae2f4
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

7,208
return-nginx-chartseture0.1.01 of 1See more

return-nginx-chart seture 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
seyiogunniran/my-nginx:1.03a0ed39e5830
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,294
ccx-monitoringseveralnines0.6.213 of 7See more

ccx-monitoring severalnines 0.6.21

3 of the 7 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
openssl@3.5.4-r0
3.5.8-r0
victoriametrics/victoria-metrics:v1.120.0a1cb2f3dfd45
openssl@3.5.0-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

7,718
shopwareshopware-storeVerified publisher2.1.21 of 5See more

shopware shopware-store 2.1.2

1 of the 5 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
rustfs/rustfs:1.0.0-alpha.738e467b32af3f
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

4,098
bffshortlink0.2.11 of 1See more

bff shortlink 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,691
linkshortlink0.7.31 of 1See more

link shortlink 0.7.3

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,674
link-uishortlink0.7.51 of 1See more

link-ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,317
uishortlink0.7.51 of 1See more

ui shortlink 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,317
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mcpuse/inspector:latest91b25e3eb604
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,254
sibylsibyl0.2.01 of 1See more

sibyl sibyl 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/bensoer/sibyl:v0.2.06dca4455fde3
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,021
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:18.43a82e1f56c8f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,681
moksi-gitops0.16.41 of 2See more

mok si-gitops 0.16.4

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
quay.io/shivering-isles/postfix:3.11.70f40af2070c8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

664
nut-exportersi-gitops0.5.01 of 1See more

nut-exporter si-gitops 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

811
frontendsignalen4.24.01 of 1See more

frontend signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
signalen/frontend:2.27.81ab79cb7fe21
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,157
postgresqlsignoz0.0.21 of 1See more

postgresql signoz 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,667
ctlogsigstoreVerified publisher0.2.681 of 4See more

ctlog sigstore 0.2.68

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,749
counter-dhlsikademo0.3.02 of 3See more

counter-dhl sikademo 0.3.0

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ondrejsika/counter:latestd95eaeee2172
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,910
gordy-redissikademo0.1.01 of 1See more

gordy-redis sikademo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

985

Container images carrying it

1,625 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/promhippie/prometheus-vcd-sd:2.12.175b05355d439
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/promhippie/scw-exporter:2.15.11952125f8423
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.8-r0
1
quay.io/seamware/did-helper:0.6.0799c5f566952
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
openssl@3.5.6-r0
3.5.8-r0
1
quay.io/shesselink81/anna-nginx:v1.31.1120c19fa8a918
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/shesselink81/hesselinkme-nginx:v1.31.114f43beb13fc2
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/shivering-isles/postfix:3.11.70f40af2070c8
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.8-r0
1
quay.io/zncdatadev/kafka-operator:0.4.00a0b4c39c1ba
openssl@3.5.7-r0
3.5.8-r0
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/gitlab-ci-utils/curl-jq:latestb564745b6cb0
openssl@3.5.7-r1
3.5.8-r0
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.8-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.8-r0
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.8-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.8-r0
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.