CVE-2026-2673
HighAdvisory
Published 13 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 37th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 554
- of 17,787 indexed, latest versions
- Container images
- 561
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 554 of 17,787 indexed charts deploy, on 561 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| opensslapk | 3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+9 more | 3.5.6-r0, 3.6.1-r3 | 432 |
| openssldeb | 3.5.1-1, 3.5.1-1+deb13u1, 3.5.3-1ubuntu2, 3.5.4-1~deb13u1+2 more | 3.5.3-1ubuntu3.3, 3.5.5-1~deb13u2 | 124 |
| nodejsdeb | 16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 more | no fix listed | 5 |
- OSV records
- CGA-67j4-8hm8-w6grALPINE-CVE-2026-2673DEBIAN-CVE-2026-2673UBUNTU-CVE-2026-2673
- Also known as
- CGA-cjvr-gj7w-mw5f, CGA-g6w5-5h7c-xmc7, CGA-jrm8-5h8q-3f9c, CGA-pr4f-6gqh-h4cw, CGA-r4h6-4294-rmgg, USN-8155-1
Charts affected
554 by stars
Container images carrying it
561 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.