StackRadar

CVE-2026-22796

Medium

Advisory

Published 27 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,262
of 17,813 indexed, latest versions
Container images
2,524
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-22796 affecting package openssl for versions less than 3.3.5-3

Carried by container images the latest versions of 2,262 of 17,813 indexed charts deploy, on 2,524 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+93 more1.0.1f-1ubuntu2.27+esm12, 1.0.2g-1ubuntu4.20+esm14, 1.1.1-1ubuntu2.1~18.04.23+esm7, 1.1.1f-1ubuntu2.24+esm2+5 more1,575
opensslapk3.0.7-r0, 3.0.7-r2, 3.0.8-r0, 3.0.8-r1+34 more3.0.19-r0, 3.3.6-r0, 3.5.5-r0, 3.6.1-r0948
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm320
opensslrpm3.3.5-1.azl33.3.5-31
OSV records
ALPINE-CVE-2026-22796CGA-54qp-f6pv-w9rwDEBIAN-CVE-2026-22796UBUNTU-CVE-2026-22796AZL-75299
Also known as
CGA-rpw7-8rcj-25xj, USN-7980-1, USN-7980-2

Charts affected

2,262 by stars
ChartLatestAffected imagesRadar Score
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
openssl@3.3.4-r0
3.3.6-r0

Open the chart page →

1,197
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2

Open the chart page →

3,185
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
3.0.18-1~deb12u2

Open the chart page →

9,738
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
3.0.18-1~deb12u2

Open the chart page →

3,196
yearningxxl-job-adminVerified publisher0.2.31 of 1See more

yearning xxl-job-admin 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
yeelabs/yearning:v3.1.81576c002d1df
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

641
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.6-r0

Open the chart page →

9,526
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2

Open the chart page →

2,718
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
openssl@3.0.9-r1
3.0.19-r0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
openssl@3.0.9-r1
3.0.19-r0

Open the chart page →

5,077
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm7

Open the chart page →

2,485
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
openssl@3.0.7-r2
3.0.19-r0
zahoriaut/zahori-server:0.1.17b2de13916f3e
openssl@3.0.8-r3
3.0.19-r0

Open the chart page →

5,846
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm7
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm2

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-22796.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

7,966

Container images carrying it

2,524 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
openssl@3.3.3-r0
3.3.6-r0
1
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
nodejs@12.22.7-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.13
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm7
1
ghcr.io/linuxserver/mariadb:version-110.4.21mariabionic7a94d7e89f52
openssl@1.1.1-1ubuntu2.1~18.04.10
1.1.1-1ubuntu2.1~18.04.23+esm7
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.21
1
ghcr.io/linuxserver/papermerge:version-v2.0.198ba2dd3f0bd
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm2
1
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.7
1
ghcr.io/linuxserver/radarr:6.0.4.10291-ls2896c0948b42c14
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
nodejs@14.19.3-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.17
openssl1.0@1.0.2n-1ubuntu5.9
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm7
1.0.2n-1ubuntu5.13+esm3
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm7
1
ghcr.io/linuxserver/sonarr:4.0.16.2944-ls3008b9f2138ec50
openssl@3.5.4-r0
3.5.5-r0
1
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
nodejs@14.19.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.14
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm7
1.0.2n-1ubuntu5.13+esm3
1
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/liubin/toml-cli:v0.0.734a1da9f0f83
openssl@3.0.7-r0
3.0.19-r0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
openssl@3.3.1-r3
3.3.6-r0
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
openssl@3.0.2-0ubuntu1.29
no fix listed
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
openssl@3.3.2-r4
3.3.6-r0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
openssl@3.3.0-r2
3.3.6-r0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.7
1
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
openssl@3.3.5-r0
3.3.6-r0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
openssl@3.0.8-r0
3.0.19-r0
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
openssl@3.3.4-r0
3.3.6-r0
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
openssl@3.5.0-r0
3.5.5-r0
1
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
openssl@3.3.2-r0
3.3.6-r0
1
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
openssl@3.3.2-r0
3.3.6-r0
1
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
openssl@3.3.4-r0
3.3.6-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
openssl@3.0.15-1~deb12u1
3.0.18-1~deb12u2
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
openssl@3.5.4-1~deb13u1
3.5.4-1~deb13u2
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
openssl@3.0.17-1~deb12u3
3.0.18-1~deb12u2
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
openssl@3.5.1-1
3.5.4-1~deb13u2
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
openssl@3.5.1-1
3.5.4-1~deb13u2
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.7
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.7
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.7
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.7
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.7
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.7
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
openssl@3.5.1-r0
3.5.5-r0
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
openssl@3.0.8-r0
3.0.19-r0
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
openssl@3.0.8-r0
3.0.19-r0
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
openssl@3.3.3-r0
3.3.6-r0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
openssl@3.3.2-r4
3.3.6-r0
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
openssl@3.0.11-1~deb12u2
3.0.18-1~deb12u2
1
ghcr.io/monicahq/monica-next:main8be69156acbb
openssl@3.5.1-1
3.5.4-1~deb13u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.