StackRadar

CVE-2026-27448

Medium

Advisory

Published 16 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
305
of 17,781 indexed, latest versions
Container images
186
deployed by those charts
Fix available
2 of 2
affected packages

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

Carried by container images the latest versions of 305 of 17,781 indexed charts deploy, on 186 images.

Affected packageAffected versionsFixed inImages
pyopensslpypi16.2.0, 17.3.0, 17.5.0, 18.0.0+18 more26.0.0186
pyopenssldeb17.5.0-1ubuntu1, 23.2.0-117.5.0-1ubuntu1+esm1, 23.2.0-1ubuntu0.14
OSV records
GHSA-vp96-hxj8-p424UBUNTU-CVE-2026-27448
Also known as
PYSEC-2026-2268, USN-8115-1, USN-8335-1

Charts affected

305 by stars
ChartLatestAffected imagesRadar Score
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pyopenssl@25.1.0
26.0.0

Open the chart page →

7,628
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
library/mysql:8.07dcddc01f13b
pyopenssl@25.3.0
26.0.0

Open the chart page →

20,190
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyopenssl@19.0.0
26.0.0

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyopenssl@19.0.0
26.0.0

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-27448.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
pyopenssl@19.1.0
26.0.0

Open the chart page →

2,643

Container images carrying it

186 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/mysql:8.07dcddc01f13b
pyopenssl@25.3.0
26.0.0
89
library/mysql:5.74bc6bc963e6d
pyopenssl@20.0.1
26.0.0
22
library/mysql:8:8.4:8.4.11b3b90af2a655
pyopenssl@25.3.0
26.0.0
16
library/mysql:9.7.2257388edf9c8
pyopenssl@25.3.0
26.0.0
6
apache/superset:6.1.0:latest16b50bbef664
pyopenssl@25.3.0
26.0.0
3
mysql/mysql-server:latestd6c8301b7834
pyopenssl@22.0.0
26.0.0
3
amancevice/superset:0.35.212a0a9e66550
pyopenssl@19.1.0
26.0.0
2
cs3org/wopiserver:v9.4.202a9e78757b4
pyopenssl@23.0.0
26.0.0
2
larribas/mlflow:1.9.105ccb0b46bfb
pyopenssl@19.1.0
26.0.0
2
library/mysql:8.2.0212fe73edca5
pyopenssl@23.2.0
26.0.0
2
library/mysql:8.4.2ac80b6e09e5b
pyopenssl@24.1.0
26.0.0
2
library/mysql:9.7.2b2cf29815e62
pyopenssl@25.3.0
26.0.0
2
lncm/specter-desktop:v1.10.536eaa06f99f4
pyopenssl@20.0.1
26.0.0
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
pyopenssl@19.1.0
26.0.0
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
pyopenssl@17.5.0
26.0.0
2
ghcr.io/plausible/community-edition:v3.2.133e60bfb40f2
pyopenssl@25.0.0
26.0.0
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
pyopenssl@21.0.0
26.0.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
pyopenssl@19.0.0
26.0.0
2
alerta/alerta-web:8.5.04786b9eaa606
pyopenssl@21.0.0
26.0.0
1
amd64/mysql:5.7e20a653e0f51
pyopenssl@20.0.1
26.0.0
1
anchore/anchore-engine:v0.10.0bde9eedf639d
pyopenssl@20.0.1
26.0.0
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
pyopenssl@19.1.0
26.0.0
1
apache/airflow:2.8.4-python3.964e58748b6b9
pyopenssl@24.1.0
26.0.0
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
pyopenssl@24.2.1
26.0.0
1
apache/airflow:2.8.1e5560ad0b86e
pyopenssl@23.3.0
26.0.0
1
appwrite/appwrite:1.9.01aaa70127114
pyopenssl@25.3.0
26.0.0
1
aristidetm/basic-notebook:3.6.5469dbc951224
pyopenssl@24.1.0
26.0.0
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
pyopenssl@24.1.0
26.0.0
1
assistiot/authorization_db:latestc3adbab6a3e7
pyopenssl@23.2.0
26.0.0
1
baserow/backend:1.31.1e0b3c8130b91
pyopenssl@24.1.0
26.0.0
1
baserow/baserow:1.30.1df0c42eb67e8
pyopenssl@24.1.0
26.0.0
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
pyopenssl@19.1.0
26.0.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pyopenssl@24.2.1
26.0.0
1
bnjbvr/kresus:0.22.137e216b182c8
pyopenssl@24.3.0
26.0.0
1
cloudve/ttyd:latestd79c1c5881c0
pyopenssl@19.1.0
26.0.0
1
copyparty/ac:1.19.200a0a8605062c
pyopenssl@25.0.0
26.0.0
1
dannielkil/book-db:latest433290c5c1db
pyopenssl@24.1.0
26.0.0
1
daskdev/dask:1.1.04ecd7bc35500
pyopenssl@18.0.0
26.0.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
pyopenssl@18.0.0
26.0.0
1
datamate/seafile-professional:11.0.202dd66b722464
pyopenssl@25.1.0
26.0.0
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
pyopenssl@24.1.0
26.0.0
1
ddosify/selfhosted_alaz_backend:2.3.11e5be48b37348
pyopenssl@24.1.0
26.0.0
1
ddosify/selfhosted_backend:3.2.93c11e3182652
pyopenssl@24.1.0
26.0.0
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
pyopenssl@24.1.0
26.0.0
1
deconzcommunity/deconz:2.12.066541bbb78952
pyopenssl@19.0.0
26.0.0
1
deepflowce/mysql:8.0.313d7ae561cf60
pyopenssl@19.1.0
26.0.0
1
devopstales/kubedash:3.1.08bb837da5aec
pyopenssl@25.0.0
26.0.0
1
devopstales/trivy-operator:2.575136aa7a26e
pyopenssl@23.0.0
26.0.0
1
douz/helpdesk:latest4384103d0219
pyopenssl@19.1.0
26.0.0
1
dysnix/pritunl:v1.29-r819951e3e7a32
pyopenssl@19.1.0
26.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.