CVE-2026-22796
MediumAdvisory
Published 27 Jan 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,264
- of 17,828 indexed, latest versions
- Container images
- 2,520
- deployed by those charts
- Fix available
- 4 of 5
- affected packages
CVE-2026-22796 affecting package openssl for versions less than 3.3.5-3
Carried by container images the latest versions of 2,264 of 17,828 indexed charts deploy, on 2,520 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+93 more | 1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.1.1-1ubuntu2.1~18.04.23+esm7, 1.1.1f-1ubuntu2.24+esm2+5 more | 1,573 |
| opensslapk | 3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+34 more | 3.0.19-r0, 3.3.6-r0, 3.5.5-r0, 3.6.1-r0 | 946 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 more | no fix listed | 22 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more | 1.0.2n-1ubuntu5.13+esm3 | 20 |
| opensslrpm | 3.3.5-1.azl3 | 3.3.5-3 | 1 |
- OSV records
- ALPINE-CVE-2026-22796CGA-54qp-f6pv-w9rwDEBIAN-CVE-2026-22796UBUNTU-CVE-2026-22796AZL-75299
- Also known as
- CGA-rpw7-8rcj-25xj, USN-7980-1, USN-7980-2
Charts affected
2,264 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| xkopsxkops | 0.1.0 | 4 of 5See more | 13,925 |
| xlinexline | 0.0.1 | 1 of 1See more | 2,166 |
| atlas-operatorxxl-job-adminVerified publisher | 0.7.11 | 1 of 1See more | 1,197 |
| dingtalk-botxxl-job-adminVerified publisher | 0.1.2 | 1 of 2See more | 3,186 |
| nightingalexxl-job-adminVerified publisher | 0.2.11 | 1 of 6See more | 9,743 |
| pgcatxxl-job-adminVerified publisher | 0.3.3 | 1 of 1See more | 3,197 |
| yearningxxl-job-adminVerified publisher | 0.2.3 | 1 of 1See more | 641 |
| ygdrassil-monitoringygdrassilVerified publisher | 0.4.0 | 1 of 10See more | 9,528 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,638 |
| zahori-consulzahoriVerified publisher | 1.0.1 | 2 of 2See more | 5,077 |
| zahori-schedulerzahoriVerified publisher | 1.0.1 | 1 of 1See more | 2,485 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 2 of 2See more | 5,847 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,297 |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 7,966 |
Container images carrying it
2,520 by charts deploying them
A fixed version is listed for 4 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| censedata/ | ebfffb9dd4c0 | openssl | 3.3.6-r0 | 1 |
| ceresdb/ | 53b2d0dbba1f | openssl | 1.1.1f-1ubuntu2.24+esm2 | 1 |
| cesanta/ | 98e0307e0d2d | openssl | 3.5.5-r0 | 1 |
| chainflag/ | ac642796bcb6 | openssl | 3.5.5-r0 | 1 |
| chandanteekinavar/ | 6de5bd44a325 | openssl | 3.3.6-r0 | 1 |
| checkmk/ | c11b422210c4 | openssl | no fix listed | 1 |
| chetangautamm/ | b4b94155ff5a | openssl | 1.0.1f-1ubuntu2.27+esm12 | 1 |
| chetangautamm/ | e7f7049e1544 | openssl | 1.1.1f-1ubuntu2.24+esm2 | 1 |
| cheveo/ | 82240f890884 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| cheyang/ | 46cc34755493 | openssl | 1.0.2g-1ubuntu4.20+esm14 | 1 |
| chibisafe/ | 836467a50792 | openssl | 3.5.5-r0 | 1 |
| chibisafe/ | 3da4fcbc1a18 | openssl | 3.5.5-r0 | 1 |
| chirpstack/ | fb7667fe037f | openssl | 3.0.19-r0 | 1 |
| chirpstack/ | c0bbbb7a3f1e | openssl | 3.0.19-r0 | 1 |
| chriseaton/ | 54c3384ce701 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| christianhuth/ | c07f414a3e4b | openssl | 3.3.6-r0 | 1 |
| circleci/ | 4d8d0ae5efc3 | openssl | 3.0.19-r0 | 1 |
| circleci/ | 9bdc62f02162 | openssl | 1.1.1f-1ubuntu2.24+esm2 | 1 |
| ciscolabs/ | 36d02faad958 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| citizenstig/ | b81c818ccb86 | openssl | 1.0.2g-1ubuntu4.20+esm14 | 1 |
| ciuse99/ | d72768245ef5 | openssl | 3.3.6-r0 | 1 |
| ckan/ | ef8e5d3e6be1 | openssl | no fix listed | 1 |
| ckulka/ | 434bdd162247 | openssl | 3.0.18-1~deb12u2 | 1 |
| clickhouse/ | 1ffa82edee00 | openssl | 1.1.1f-1ubuntu2.24+esm2 | 1 |
| clickhouse/ | 2e6587b81a26 | openssl | 1.1.1f-1ubuntu2.24+esm2 | 1 |
| clickhouse/ | 512bb8a21483 | openssl | 1.1.1f-1ubuntu2.24+esm2 | 1 |
| clickhouse/ | 810861a2e2d0 | openssl | no fix listed | 1 |
| clickhouse/ | 84d05b9c205e | openssl | no fix listed | 1 |
| clickhouse/ | 8745843b17f9 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| clickhouse/ | 92098d3b31dd | openssl | no fix listed | 1 |
| clickhouse/ | a65ca89ddbe8 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| clickhouse/ | a73b5c0fb6f8 | openssl | no fix listed | 1 |
| clickhouse/ | b627d7a9bc0e | openssl | 3.0.2-0ubuntu1.21 | 1 |
| clickhouse/ | cd450891db46 | openssl | 3.3.6-r0 | 1 |
| clickhouse/ | d73903d1b61d | openssl | no fix listed | 1 |
| clickhouse/ | dc5658853ce1 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| clickhouse/ | e019438e1e05 | openssl | 3.0.2-0ubuntu1.21 | 1 |
| cloudflare/ | eb5c9324efe3 | openssl | 3.0.18-1~deb12u2 | 1 |
| cloudnativelabs/ | 0ec7cd73f43f | openssl | 3.0.19-r0 | 1 |
| cloudve/ | af56e77ca587 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm7 | 1 |
| cloudve/ | d79c1c5881c0 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm7 | 1 |
| clowder/ | 11f3d844e4c0 | openssl | 3.0.18-1~deb12u2 | 1 |
| clowder/ | fe97882672ca | openssl | 3.5.5-r0 | 1 |
| clowder/ | 14155326c7b9 | openssl | 3.0.18-1~deb12u2 | 1 |
| clowder/ | bf146f1ca24f | openssl | 3.0.18-1~deb12u2 | 1 |
| clsen2024/ | 1156cd87c8fb | openssl | 3.3.6-r0 | 1 |
| clsen2024/ | 0ba9eff852c5 | openssl | 3.3.6-r0 | 1 |
| clsen2024/ | 51b1d45961cd | openssl | 3.3.6-r0 | 1 |
| clsen2024/ | efb1586c8299 | openssl | 3.3.6-r0 | 1 |
| codecov/ | 534bc4778073 | openssl | 3.0.19-r0 | 1 |