StackRadar

CVE-2026-18798

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
73rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,708
of 17,813 indexed, latest versions
Container images
1,617
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,708 of 17,813 indexed charts deploy, on 1,617 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,173
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2427
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
OSV records
ALPINE-CVE-2026-18798DEBIAN-CVE-2026-18798UBUNTU-CVE-2026-18798
Also known as
USN-8678-1

Charts affected

1,708 by stars
ChartLatestAffected imagesRadar Score
mw-kube-agent-v3middleware-labsVerified publisher1.8.51 of 2See more

mw-kube-agent-v3 middleware-labs 1.8.5

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent-config-updater:1.21.0d4edc3f244f4
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,101
parent-chartmid-proje0.1.02 of 3See more

parent-chart mid-proje 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
youssef11gaber10/flask-service:latest9c727fcfde76
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
youssef11gaber10/react-service-k8s:latestbe23f058edb6
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,832
mini-blogmini-blog-helm0.1.02 of 3See more

mini-blog mini-blog-helm 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
beyzkaya/blog-frontend:v1.0.0bf412d75c510
openssl@3.5.0-r0
3.5.8-r0
library/postgres:159b1d34adbce1
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

13,314
MINTmint8.0.23 of 15See more

MINT mint 8.0.2

3 of the 15 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
alpine/curl:latestb9c839d47281
openssl@3.5.7-r0
3.5.8-r0
library/postgres:13-alpinefb9065b6e3e2
openssl@3.5.4-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

114,972
helmmirasys-chart0.1.01 of 4See more

helm mirasys-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,470
verapdfmlohrVerified publisher1.4.01 of 1See more

verapdf mlohr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
verapdf/rest:v1.30.2341359ac6af5
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

495
mo-backupmogeniusOfficialVerified publisher1.0.291 of 1See more

mo-backup mogenius 1.0.29

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/mogenius/mo-backup:latest4f89afef9010
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

814
mo-backup-mysqlmogeniusVerified publisher1.0.291 of 1See more

mo-backup-mysql mogenius 1.0.29

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/mogenius/mo-backup:latest4f89afef9010
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

814
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,463
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

15,279
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

2,637
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,463
mollysocketmollysocket-wrenixVerified publisher0.1.141 of 2See more

mollysocket mollysocket-wrenix 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.3c4a11ae9a1cb
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,554
gar-credential-providermondu-aiVerified publisher0.2.11 of 1See more

gar-credential-provider mondu-ai 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

710
cloudflare-tunnel-remotemoonswitchVerified publisher0.1.41 of 1See more

cloudflare-tunnel-remote moonswitch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latest51c9cefcb456
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

572
discoursemozilla3.0.71 of 3See more

discourse mozilla 3.0.7

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
adguard-homemt1905024.0.122 of 2See more

adguard-home mt190502 4.0.12

2 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.737fbf01d73ecb
openssl@3.5.5-r0
3.5.8-r0
mikefarah/yq:latestcfc4eee65859
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,168
codimdmt1905027.2.21 of 3See more

codimd mt190502 7.2.2

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,699
commafeedmt1905028.2.02 of 3See more

commafeed mt190502 8.2.0

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
athou/commafeed:6.2.0-postgresql5e388351df1a
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,821
copilot-apimt1905022.3.01 of 1See more

copilot-api mt190502 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/bouquet2/copilot-api-docker:v0.7.06b0507a20602
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

489
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,009
memosmt1905027.3.21 of 3See more

memos mt190502 7.3.2

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,668
minifluxmt1905021.1.62 of 3See more

miniflux mt190502 1.1.6

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
miniflux/miniflux:2.2.18a3ca6bbc1f74
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,744
open-webuimt1905022.3.101 of 3See more

open-webui mt190502 2.3.10

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,699
paperless-ngxmt1905027.6.142 of 4See more

paperless-ngx mt190502 7.6.14

2 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

12,314
radicalemt1905024.1.11 of 1See more

radicale mt190502 4.1.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
tomsquest/docker-radicale:3.6.1.0a594c624c5a6
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,544
umamimt1905028.1.42 of 3See more

umami mt190502 8.1.4

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/umami-software/umami:3.0.328f263fe06f7
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

4,089
vaultwardenmt1905027.3.42 of 3See more

vaultwarden mt190502 7.3.4

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
vaultwarden/server:1.35.443498a94b22f
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,834
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,042
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

9,041
ingress-nginxmxytest4.15.11 of 2See more

ingress-nginx mxytest 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,542
szurubooru-clientmy0nVerified publisher0.3.11 of 1See more

szurubooru-client my0n 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
szurubooru/client:2.5880a53ca446d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

371
szurubooru-servermy0nVerified publisher0.2.51 of 3See more

szurubooru-server my0n 0.2.5

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
szurubooru/server:2.5accf2ad9fbc3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,045
apachemy-chart-repo0.1.01 of 2See more

apache my-chart-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
library/httpd:2.4979c38c2228d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,828
grafana-chartmy-personal-grafana0.1.01 of 1See more

grafana-chart my-personal-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

745
haproxy-ingressn42-gateway0.16.11 of 1See more

haproxy-ingress n42-gateway 0.16.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
quay.io/jcmoraisjr/haproxy-ingress:v0.16.16fd744191ef6
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

795
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
openssl@3.5.7-r1
3.5.8-r0

Open the chart page →

1,064
dependency-tracknaj980.0.92 of 3See more

dependency-track naj98 0.0.9

2 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
dependencytrack/apiserver:latestf1da63ed610a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
dependencytrack/frontend:latest8854a8320475
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,507
jupyterhub-metricsncsaVerified publisher1.3.04 of 5See more

jupyterhub-metrics ncsa 1.3.0

4 of the 5 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
timescale/timescaledb:latest-pg156343bdc87ca1
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

4,170
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,170
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

7,333
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,575
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,402
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,961
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

3,925
nexus-tasksnexus-tasks2.0.02 of 5See more

nexus-tasks nexus-tasks 2.0.0

2 of the 5 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-backend:2.0.0f80349eb018b
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,932
f5-waf-policy-controllernginxVerified publisher5.15.01 of 4See more

f5-waf-policy-controller nginx 5.15.0

1 of the 4 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
curlimages/curl:8.20.0b3f1fb2a51d9
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

420
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
nodejs@14.18.2-1nodesource1
no fix listed

Open the chart page →

24,394
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
nodejs@14.18.2-1nodesource1
no fix listed

Open the chart page →

25,572
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-18798.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
nodejs@14.19.3-1nodesource1
no fix listed

Open the chart page →

22,445

Container images carrying it

1,617 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

No deployed image carries CVE-2026-18798.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.