StackRadar

CVE-2026-18798

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,708
of 17,813 indexed, latest versions
Container images
1,617
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,708 of 17,813 indexed charts deploy, on 1,617 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,173
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2427
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
OSV records
ALPINE-CVE-2026-18798DEBIAN-CVE-2026-18798UBUNTU-CVE-2026-18798
Also known as
USN-8678-1

Charts affected

1,708 by stars
ChartLatestAffected imagesRadar Score
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,395
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

949
sonarrloeken-at-homeVerified publisher4.0.181 of 1See more

sonarr loeken-at-home 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
loeken/sonarr:4.0.18ad0528ab7ba0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

859
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

804
elasticvuelogic3579Verified publisher1.15.01 of 1See more

elasticvue logic3579 1.15.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
cars10/elasticvue:1.15.0efddf4fa0fd8
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,083
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

9,172
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,511
logtidelogtideVerified publisher2.1.143 of 4See more

logtide logtide 2.1.14

3 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,968
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:latest69a7170eeeda
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,857
redislsst-sqre1.2.11 of 1See more

redis lsst-sqre 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,010
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,165
lynxpromptlynxpromptVerified publisher0.1.22 of 3See more

lynxprompt lynxprompt 0.1.2

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
openssl@3.5.6-r0
3.5.8-r0
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,870
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,726
jellyfinm0nsterrr-jellyfinVerified publisher2.3.51 of 1See more

jellyfin m0nsterrr-jellyfin 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,672
kea-exporterm0nsterrr-kea-exporterVerified publisher2.2.11 of 1See more

kea-exporter m0nsterrr-kea-exporter 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,099
qbittorrentm0nsterrr-qbittorrentVerified publisher7.1.21 of 2See more

qbittorrent m0nsterrr-qbittorrent 7.1.2

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.2.34fcf15b7f265
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

764
recyclarrm0nsterrr-recyclarrVerified publisher2.7.21 of 1See more

recyclarr m0nsterrr-recyclarr 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/recyclarr/recyclarr:8.7.26e69e009e1cd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

241
routinatorm0nsterrr-routinatorVerified publisher2.3.11 of 1See more

routinator m0nsterrr-routinator 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
nlnetlabs/routinator:v0.15.2bc57d6e973c3
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

743
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-backend:latest4adf360dbf1e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

24,771
docker-mailservermailserverVerified publisher0.2.652 of 9See more

docker-mailserver mailserver 0.2.65

2 of the 9 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
openssl@3.5.2-r0
3.5.8-r0
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

11,554
plane-mcp-servermakeplaneVerified publisher1.0.01 of 2See more

plane-mcp-server makeplane 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
makeplane/plane-mcp-server:v0.3.071b7252adef0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,660
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,739
marge-botmarge-bot-helm1.3.51 of 1See more

marge-bot marge-bot-helm 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,627
ejabberdmartialblog0.3.11 of 1See more

ejabberd martialblog 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/processone/ejabberd:latest5aeb0faa39cf
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

386
mayastormayastorVerified publisher2.12.13 of 31See more

mayastor mayastor 2.12.1

3 of the 31 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
openebs/alpine-bash:4.6.0366d6c5f18c3
openssl@3.5.7-r0
3.5.8-r0
openebs/alpine-sh:4.6.0640c187dccda
openssl@3.5.7-r0
3.5.8-r0
openebs/provisioner-localpv:4.6.099f5116f5cb8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

21,494
mcp-atlassianmcp-helmVerified publisher0.2.281 of 1See more

mcp-atlassian mcp-helm 0.2.28

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,741
mcroutermcrouterVerified publisher0.2.01 of 2See more

mcrouter mcrouter 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/memcached:1.6.4226983a43c918
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,363
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

9,918
mdai-hubmdai-hubVerified publisher0.10.11 of 14See more

mdai-hub mdai-hub 0.10.1

1 of the 14 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,930
dependency-trackmediamarktsaturn1.9.22 of 2See more

dependency-track mediamarktsaturn 1.9.2

2 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
dependencytrack/frontend:4.14.200560b57a6cf
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,864
profilarrmedia-servarrVerified publisher2.3.11 of 1See more

profilarr media-servarr 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/dictionarry-hub/profilarr:2.2.0ddcdd0f34004
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

337
tinymediamanagermedia-servarrVerified publisher1.6.31 of 2See more

tinymediamanager media-servarr 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

8,196
memgraph-mcpmemgraphVerified publisher1.0.01 of 1See more

memgraph-mcp memgraph 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,749
merminmerminOfficialVerified publisher0.4.11 of 1See more

mermin mermin 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/elastiflow/mermin:v0.4.1205053c8a3e2
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

639
istio-helm-istiodmesosphere1.25.11 of 2See more

istio-helm-istiod mesosphere 1.25.1

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mesosphere/kubectl:v1.35.0-alpineea01a9387771
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,854
kube-prometheus-stackmesosphere87.16.02 of 7See more

kube-prometheus-stack mesosphere 87.16.0

2 of the 7 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
grafana/grafana:13.1.0121a7a9ece6d
openssl@3.5.7-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.8.1abb55b2165c6
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

7,524
prometheus-operatormesosphere12.11.132 of 8See more

prometheus-operator mesosphere 12.11.13

2 of the 8 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
grafana/grafana:12.3.39e1e77ade304
openssl@3.5.5-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

11,740
istio-helm-istiodmesosphere-stable1.23.61 of 2See more

istio-helm-istiod mesosphere-stable 1.23.6

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mesosphere/kubectl:v1.35.0-alpineea01a9387771
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

4,682
multusmesosphere-stable0.1.11 of 1See more

multus mesosphere-stable 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,834
metacontroller-helmmetacontroller4.17.21 of 1See more

metacontroller-helm metacontroller 4.17.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/metacontroller/metacontroller:v4.17.2d7a55ebc70b4
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

205
activityrelaymhamzahkhanVerified publisher1.0.651 of 2See more

activityrelay mhamzahkhan 1.0.65

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
yukimochi/activity-relay:v2.0.115798afb69216
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

220
miot-appmicroboxlabs0.3.31 of 1See more

miot-app microboxlabs 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

513
miot-dashboard-servermicroboxlabs0.1.11 of 1See more

miot-dashboard-server microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-dashboard-server:latest19b910920ab1
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

240
miot-docsmicroboxlabs0.1.11 of 1See more

miot-docs microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-docs:lateste09d92c61f43
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

381
miot-harnessmicroboxlabs0.7.01 of 1See more

miot-harness microboxlabs 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,212
miot-stackmicroboxlabs0.2.21 of 2See more

miot-stack microboxlabs 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

513
modulariotmicroboxlabs0.9.02 of 4See more

modulariot microboxlabs 0.9.0

2 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/microboxlabs/miot-docs:latest0307d2fd9f5c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,359
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,223
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,691
mw-autoinstrumentationmiddleware-labsVerified publisher1.2.61 of 6See more

mw-autoinstrumentation middleware-labs 1.2.6

1 of the 6 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

3,755

Container images carrying it

1,617 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

No deployed image carries CVE-2026-18798.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.