StackRadar

CVE-2026-28387

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,250
of 17,787 indexed, latest versions
Container images
2,512
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-28387 affecting package openssl for versions less than 3.3.7-2

Carried by container images the latest versions of 2,250 of 17,787 indexed charts deploy, on 2,512 images.

Affected packageAffected versionsFixed inImages
openssldeb1.1.0g-2ubuntu4.1, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1~18.04.4, 1.1.1-1ubuntu2.1~18.04.5+81 more1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23, 3.0.13-0ubuntu3.9+3 more1,598
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0904
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-25
OSV records
ALPINE-CVE-2026-28387CGA-2m6v-xf35-w7r6CGA-35qm-vc7p-cgg6DEBIAN-CVE-2026-28387UBUNTU-CVE-2026-28387AZL-81947ECHO-6fc6-4872-7ea8
Also known as
CGA-778p-whh3-f9cv, CGA-w98m-q38h-wxww, USN-8155-1, USN-8155-2

Charts affected

2,250 by stars
ChartLatestAffected imagesRadar Score
datagrokdatagrok1.0.31 of 7See more

datagrok datagrok 1.0.3

1 of the 7 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
datagrok/grok_connect:latestf5876d3aebb8
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,368
datagrok_grok_connectdatagrok1.0.01 of 1See more

datagrok_grok_connect datagrok 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
datagrok/grok_connect:latestf5876d3aebb8
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

1,665
eg-edge-stackdatawire0.0.11 of 7See more

eg-edge-stack datawire 0.0.1

1 of the 7 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

15,781
pagesdavid-pages1.0.02 of 3See more

pages david-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,233
giphy-appdavidy-helm-charts-repository0.1.21 of 1See more

giphy-app davidy-helm-charts-repository 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
davidy/giphy-app:1.0.2-arm41b2355cc23a
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

704
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,116
myfirstchartdcn-helmchartrepo0.3.01 of 1See more

myfirstchart dcn-helmchartrepo 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
sinhasaurabh09/dcn-portal:v1.2c0d08847ddbb
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

382
pagesdebasish-pages1.0.02 of 3See more

pages debasish-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,233
intel-gpu-exporterdefault-ghVerified publisher0.1.01 of 1See more

intel-gpu-exporter default-gh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,846
isponsorblocktvdefault-ghVerified publisher1.0.51 of 1See more

isponsorblocktv default-gh 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
openssl@3.3.5-r0
3.3.7-r0

Open the chart page →

546
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,656
dell-fan-controllerdell-fan-controllerVerified publisher1.0.71 of 1See more

dell-fan-controller dell-fan-controller 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

2,560
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
openssl@1.1.1f-1ubuntu2.18
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,259
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

8,154
deployhubdeployhubVerified publisher10.0.4156 of 11See more

deployhub deployhub 10.0.415

6 of the 11 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
openssl@3.5.4-r0
3.5.6-r0
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
openssl@3.5.4-r0
3.5.6-r0
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
openssl@3.6.0-r6
3.6.2-r0
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.2-r0
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.2-r0
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.2-r0

Open the chart page →

11,161
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

14,910
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,530
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

2,096
apachedevops0.1.02 of 4See more

apache devops 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.23

Open the chart page →

30,150
laraveldevops0.10.32 of 4See more

laravel devops 0.10.3

2 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.23

Open the chart page →

29,151
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

13,036
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,549
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,152
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

12,999
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

4,688
devtron-enterprisedevtron48.0.07 of 28See more

devtron-enterprise devtron 48.0.0

7 of the 28 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

66,542
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,957
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,699
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,152
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

12,999
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

4,688
devtron-enterprisedevtron-labs48.0.07 of 28See more

devtron-enterprise devtron-labs 48.0.0

7 of the 28 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

66,542
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.32 of 11See more

devtron-operator devtron-labs 0.23.3

2 of the 11 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,957
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,699
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,608
rateldgraph25.0.31 of 1See more

ratel dgraph 25.0.3

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dgraph/ratel:v25.0.34cae1ff95027
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,002
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,053
difydify1.0.03 of 4See more

dify dify 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
langgenius/dify-sandbox:0.2.009b7e8705673
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
langgenius/dify-web:1.0.0d64914ff0d6d
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

19,063
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,233
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

4,551
direktivdirektivVerified publisher0.10.02 of 6See more

direktiv direktiv 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
openssl@3.3.3-r0
3.3.7-r0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

3,470
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,384
bearhugmugsdjjudas21Verified publisher0.1.01 of 1See more

bearhugmugs djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
djjudas21/bearhugmugs:0.1.14fa898a52d97
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

704
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

7,167
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,005
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

873
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,411

Container images carrying it

2,512 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
4
bitnamilegacy/kubectl:latestcd354d5b2556
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
3
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
openssl@3.3.6-r0
3.3.7-r0
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
3
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
3
curlimages/curl:8.18.0d94d07ba9e7d
openssl@3.5.4-r0
3.5.6-r0
3
derailed/popeye:v0.22.18e68e22c7663
openssl@3.3.2-r4
3.3.7-r0
3
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
3
envoyproxy/envoy:v1.31.02bf7f042e396
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23
3
gchq/hdfs:3.3.35ec58edbb2db
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
3
grafana/grafana:11.3.0a0f881232a6f
openssl@3.3.2-r0
3.3.7-r0
3
guacamole/guacamole:1.6.0f344085e618b
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
3
jacobalberty/unifi:v10.0.162896c0ab82d33
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
openssl@3.5.4-r0
3.5.6-r0
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
openssl@3.3.2-r0
3.3.7-r0
3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
openssl@3.3.3-r0
3.3.7-r0
3
kubegems/kubegems:v1.24.10a730bcf9322a
openssl@3.5.4-r0
3.5.6-r0
3
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.6-r0
3
library/nginx:1.25:1.25.5a484819eb602
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
openssl@3.3.1-r3
3.3.7-r0
3
natsio/nats-box:0.19.28031d190c7ee
openssl@3.5.4-r0
3.5.6-r0
3
opencsghq/psql:latest57def8e77d0f
openssl@3.3.2-r4
3.3.7-r0
3
selenium/hub:3.141.5902f251d48d5f
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
3
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
3
xenondb/percona:5.7.330e26872a2b67
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
openssl@3.0.9-1
3.0.19-1~deb12u2
3
ghcr.io/dexidp/dex:v2.45.18499afd690c4
openssl@3.5.5-r0
3.5.6-r0
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
3
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
openssl@3.3.3-r0
3.3.7-r0
3
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
3
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
openssl@3.3.2-r4
3.3.7-r0
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
openssl@3.3.2-r4
3.3.7-r0
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
openssl@3.3.2-r4
3.3.7-r0
3
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
openssl@3.3.2-r4
3.3.7-r0
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
openssl@3.5.5-r0
3.5.6-r0
3
alazidis/kube-netlag:1.1.00e8c84152201
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
2
alpine/curl:8.7.1f0c1b7ca12f6
openssl@3.3.1-r0
3.3.7-r0
2
alpine/git:2.47.2062a01ad7a0e
openssl@3.3.3-r0
3.3.7-r0
2
alpine/k8s:1.32.12048f8d9c8cc7
openssl@3.5.5-r0
3.5.6-r0
2
alpine/kubectl:1.35.2ec8f734b0a10
openssl@3.5.5-r0
3.5.6-r0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.