StackRadar

CVE-2026-27448

Medium

Advisory

Published 16 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
305
of 17,781 indexed, latest versions
Container images
186
deployed by those charts
Fix available
2 of 2
affected packages

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

Carried by container images the latest versions of 305 of 17,781 indexed charts deploy, on 186 images.

Affected packageAffected versionsFixed inImages
pyopensslpypi16.2.0, 17.3.0, 17.5.0, 18.0.0+18 more26.0.0186
pyopenssldeb17.5.0-1ubuntu1, 23.2.0-117.5.0-1ubuntu1+esm1, 23.2.0-1ubuntu0.14
OSV records
GHSA-vp96-hxj8-p424UBUNTU-CVE-2026-27448
Also known as
PYSEC-2026-2268, USN-8115-1, USN-8335-1

Charts affected

305 by stars
ChartLatestAffected imagesRadar Score
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pyopenssl@25.1.0
26.0.0

Open the chart page →

7,628
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pyopenssl@25.3.0
26.0.0

Open the chart page →

20,190
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyopenssl@19.0.0
26.0.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyopenssl@19.0.0
26.0.0

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
pyopenssl@19.1.0
26.0.0

Open the chart page →

2,643

Container images carrying it

186 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
errbotio/errbot:6.1.900ee4e0953ab
pyopenssl@21.0.0
26.0.0
1
evk02/mlflow:2.2.1ef6ff257ef35
pyopenssl@23.0.0
26.0.0
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
pyopenssl@22.0.0
26.0.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
pyopenssl@25.0.0
pyopenssl@23.2.0-1
26.0.0
23.2.0-1ubuntu0.1
1
galaxy/cloudman-server:lateste5c265fe9fcd
pyopenssl@22.0.0
26.0.0
1
galaxy/galaxy-init:v18.010267bad550e6
pyopenssl@17.5.0
26.0.0
1
gethue/hue:4.11.011b649636e68
pyopenssl@22.0.0
26.0.0
1
gethue/hue:4.10.05702b2c37ff9
pyopenssl@20.0.1
26.0.0
1
gethue/hue:latest7d5c1b9f8a79
pyopenssl@25.1.0
26.0.0
1
goofball222/pritunl:1.30.3070.5943c0743701d4
pyopenssl@19.1.0
26.0.0
1
goofball222/pritunl:1.32.3602.807bf26032dfce
pyopenssl@22.1.0
26.0.0
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
pyopenssl@25.0.0
26.0.0
1
grafana/oncall:v1.16.5499851658393
pyopenssl@25.1.0
26.0.0
1
hayk96/alerta-web:9.0.486377705e9e3
pyopenssl@24.2.1
26.0.0
1
helga09/my_sql_shoes:v1.1.1a03657d97897
pyopenssl@22.0.0
26.0.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
pyopenssl@23.2.0
26.0.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
pyopenssl@23.2.0
26.0.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pyopenssl@20.0.1
26.0.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
pyopenssl@19.0.0
26.0.0
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
pyopenssl@23.2.0
26.0.0
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
pyopenssl@20.0.0
26.0.0
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
pyopenssl@20.0.1
26.0.0
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
pyopenssl@23.2.0
26.0.0
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
pyopenssl@19.1.0
26.0.0
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
pyopenssl@19.1.0
26.0.0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
pyopenssl@23.2.0
26.0.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pyopenssl@22.0.0
26.0.0
1
langgenius/dify-api:1.0.0066035f93856
pyopenssl@24.3.0
26.0.0
1
lib42/deluge:20c4d1d326f95
pyopenssl@23.0.0
26.0.0
1
library/mysql:8.4.3106d5197fd8e
pyopenssl@24.2.1
26.0.0
1
library/mysql:8.4.113466ba4a4828
pyopenssl@25.3.0
26.0.0
1
library/mysql:8.0.303c1aab708f6e
pyopenssl@19.1.0
26.0.0
1
library/mysql:885b9bf2e29cf
pyopenssl@25.3.0
26.0.0
1
library/mysql:8.4.108dbcf531a03a
pyopenssl@25.3.0
26.0.0
1
library/mysql:9.0.192dc86967801
pyopenssl@24.1.0
26.0.0
1
library/mysql:8.0.41bf577825b52a
pyopenssl@24.2.1
26.0.0
1
library/mysql:8.0.39ccb8f749bb5e
pyopenssl@24.1.0
26.0.0
1
library/mysql:8.0.40d58ac93387f6
pyopenssl@24.2.1
26.0.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pyopenssl@25.1.0
26.0.0
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
pyopenssl@20.0.1
26.0.0
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pyopenssl@19.0.0
26.0.0
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pyopenssl@19.1.0
26.0.0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pyopenssl@25.1.0
26.0.0
1
linuxserver/deluge:18.04.10ac871624394
pyopenssl@17.5.0
pyopenssl@17.5.0-1ubuntu1
26.0.0
17.5.0-1ubuntu1+esm1
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pyopenssl@17.5.0
pyopenssl@17.5.0-1ubuntu1
26.0.0
17.5.0-1ubuntu1+esm1
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pyopenssl@17.5.0
pyopenssl@17.5.0-1ubuntu1
26.0.0
17.5.0-1ubuntu1+esm1
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pyopenssl@19.1.0
26.0.0
1
localstack/localstack:3.19d278167f2b7
pyopenssl@24.0.0
26.0.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
pyopenssl@22.0.0
26.0.0
1
lsstsqre/prepuller:latest19c2dfc4e4ff
pyopenssl@20.0.1
26.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.