StackRadar

CVE-2026-28387

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,247
of 17,790 indexed, latest versions
Container images
2,511
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-28387 affecting package openssl for versions less than 3.3.7-2

Carried by container images the latest versions of 2,247 of 17,790 indexed charts deploy, on 2,511 images.

Affected packageAffected versionsFixed inImages
openssldeb1.1.0g-2ubuntu4.1, 1.1.0g-2ubuntu4.3, 1.1.1-1ubuntu2.1~18.04.4, 1.1.1-1ubuntu2.1~18.04.5+81 more1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23, 3.0.13-0ubuntu3.9+3 more1,599
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-25
OSV records
ALPINE-CVE-2026-28387CGA-2m6v-xf35-w7r6CGA-35qm-vc7p-cgg6DEBIAN-CVE-2026-28387UBUNTU-CVE-2026-28387AZL-81947ECHO-6fc6-4872-7ea8
Also known as
CGA-778p-whh3-f9cv, CGA-w98m-q38h-wxww, USN-8155-1, USN-8155-2

Charts affected

2,247 by stars
ChartLatestAffected imagesRadar Score
opentelemetry-demogpg-dev0.33.815 of 27See more

opentelemetry-demo gpg-dev 0.33.8

15 of the 27 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
grafana/grafana:11.3.1fa801ab6e1ae
openssl@3.3.2-r0
3.3.7-r0
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
openssl@3.3.2-r0
3.3.7-r0
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
openssl@3.3.2-r0
3.3.7-r0
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/open-telemetry/demo:1.12.0-cartservice89730afa0b5d
openssl@3.3.2-r0
3.3.7-r0
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
openssl@3.3.2-r0
3.3.7-r0
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
openssl@3.3.0-r2
3.3.7-r0
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

49,362
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

1,562
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,797
grafana-cloud-onboardinggrafana0.4.71 of 5See more

grafana-cloud-onboarding grafana 0.4.7

1 of the 5 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

4,681
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

3,370
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

8,269
grafana-dashboard-convertergrafana-dashboard-converterVerified publisher0.3.101 of 1See more

grafana-dashboard-converter grafana-dashboard-converter 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

907
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9

Open the chart page →

7,956
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23

Open the chart page →

4,632
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

5,347
armada-executorgresearch0.22.81 of 1See more

armada-executor gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gresearch/armada-executor:latest393aff4aa8f2
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

714
armada-lookout-ingestergresearch0.22.81 of 1See more

armada-lookout-ingester gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gresearch/armada-lookout-ingester:latest3df14cda1855
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

714
armada-lookout-migrationgresearch0.22.81 of 1See more

armada-lookout-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gresearch/armada-lookout:latestf5e3226f1d33
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

714
armada-scheduler-migrationgresearch0.22.81 of 1See more

armada-scheduler-migration gresearch 0.22.8

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gresearch/armada-scheduler:latest6141a6213fcb
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

714
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,692
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,221
act-runnergringolitoVerified publisher0.2.01 of 1See more

act-runner gringolito 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

2,598
routergroundcover1.12.3623 of 7See more

router groundcover 1.12.362

3 of the 7 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
openssl@3.5.4-1~deb13u2+e1
3.5.5-1~deb13u2
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
openssl@3.5.4-1~deb13u2+e1
3.5.5-1~deb13u2

Open the chart page →

6,070
gwangju_2-3gwangju2-30.1.03 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
clsen2024/gwangju_2-3:service-b-10ba9eff852c5
openssl@3.3.1-r3
3.3.7-r0
clsen2024/gwangju_2-3:service-a-151b1d45961cd
openssl@3.3.1-r3
3.3.7-r0
clsen2024/gwangju_2-3:service-c-1efb1586c8299
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

6,506
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,949
librechat-exporterhajowielandVerified publisher1.0.01 of 1See more

librechat-exporter hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,301
minifluxhajowielandVerified publisher1.0.01 of 1See more

miniflux hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,113
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

3,256
ubooquityhalkeye0.1.11 of 1See more

ubooquity halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
linuxserver/ubooquity:2.1.2-ls369932d6759112
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

4,304
hatchet-hahatchetOfficialVerified publisher0.19.02 of 8See more

hatchet-ha hatchet 0.19.0

2 of the 8 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

7,407
hatchet-stackhatchetOfficialVerified publisher0.19.02 of 8See more

hatchet-stack hatchet 0.19.0

2 of the 8 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

7,407
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

9,178
hdx-oss-v2hdx-oss-v20.8.42 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

2 of the 5 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.7-alpine258d43821508
openssl@3.5.4-r0
3.5.6-r0
library/mongo:5.0.14-focal50cae5081ab4
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,751
heliconehelicone0.1.423 of 14See more

helicone helicone 0.1.42

3 of the 14 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
openssl@3.0.2-0ubuntu1.9
3.0.2-0ubuntu1.23
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

25,183
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

5,586
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,862
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nodejs@16.19.1-deb-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.21
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

10,673
pageshelm-chart-repos-camden1.0.02 of 3See more

pages helm-chart-repos-camden 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,036
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

4,651
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,829
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
iofog/router:2.0.17260cf861479
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

24,171
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

949
monitoring-stackhelm-charts-alexis-carbillet0.1.01 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

1 of the 11 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

10,642
nginx-charthelm-chart-sample-app0.1.01 of 1See more

nginx-chart helm-chart-sample-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
rraahul/test:latestbfe2c1183bc0
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,599
teslamate-apihelm-charts-darox1.0.11 of 1See more

teslamate-api helm-charts-darox 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
tobiasehlert/teslamateapi:1.20.2cf09259ad0ea
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,043
twampyhelm-charts-darox0.0.21 of 1See more

twampy helm-charts-darox 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dariomader/twampy:v0.0.2d2f4a8c5e690
openssl@3.2.0-r0
3.6.2-r0

Open the chart page →

2,064
kube-benchhelm-charts-nr0.1.171 of 1See more

kube-bench helm-charts-nr 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
openssl@3.3.1-r1
3.3.7-r0

Open the chart page →

1,623
kube-downscalerhelm-charts-nr0.7.61 of 1See more

kube-downscaler helm-charts-nr 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

4,310
locusthelm-charts-nr0.32.41 of 1See more

locust helm-charts-nr 0.32.4

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,817
node-local-dnshelm-charts-nr2.1.41 of 1See more

node-local-dns helm-charts-nr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,248
chart-bookhelm-deploy-book0.1.01 of 3See more

chart-book helm-deploy-book 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
dannielkil/book-frontend:latest937993927694
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,148
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

5,816
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

9,485
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2026-28387.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
openssl@3.0.2-0ubuntu1.23
no fix listed

Open the chart page →

10,027

Container images carrying it

2,511 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
istio/install-cni:1.29.0ce27c9ce43c8
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
istio/operator:1.10.3655eefa11c84
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/operator:1.12.06cfce8a071b9
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
istio/operator:1.18.270f9d1fe5fff
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
istio/pilot:1.10.0294ca55bd1cc
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/pilot:1.29.0325156535773
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
istio/pilot:1.23.69c3d6a218181
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
istio/pilot:1.16.0ac0284d75ec9
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
1
istio/pilot:1.17.1ce9d87606701
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
1
istio/pilot:1.15.2db08d6963975
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
1
istio/pilot:1.10.3e7e110a421c2
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/pilot:1.29.1f8b0e412ac4a
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
istio/proxyv2:1.9.687a9db561d2e
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/proxyv2:1.10.088c6c693e67a
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/proxyv2:1.14.1df69c1a7af7c
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm3
1
istio/ztunnel:1.25.005f3972d80a9
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ivanjosipovic/ingress-nginx-validate-jwt:1.13.995089339a68ae
openssl@3.3.3-r0
3.3.7-r0
1
ixsystems/truecommand:3.2.019c218455cd2
openssl@3.5.1-1
3.5.5-1~deb13u2
1
jacobalberty/unifi:v7.1.664a3616625dda
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8
1
jaedb/iris:latest048cfbf58d57
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jaegertracing/jaeger:2.9.0e128b9adbb29
openssl@3.5.1-r0
3.5.6-r0
1
jakowenko/double-take:1.6.0b858bac9e32a
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
openssl@3.3.2-r0
3.3.7-r0
1
janzo83/serviceexample:latestfb3c4ac36f3e
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
jeboehm/mailserver-filter:5.0.92e756949e537d
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
openssl@3.5.2-r0
3.5.6-r0
1
jedi132000/nextapp:latestdc2a81e92f23
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
jellyfin/jellyfin:10.11.81694ff069f0c
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
jellyfin/jellyfin:10.11.717285f9cce63
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jellyfin/jellyfin:10.11.6333b64771663
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
jellyfin/jellyfin:10.10.77ae36aab93ef
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jellyfin/jellyfin:10.10.696b09723b22f
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
jhaals/yopass:11.17.026873480863b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
jhaals/yopass:12.5.0916a1cf45d36
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
openssl@3.3.2-r0
3.3.7-r0
1
jhipster/jhipster-registry:latest7184525acd4d
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm3
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jkroepke/github_exporter:1.8.03d850992786d
openssl@3.5.4-r0
3.5.6-r0
1
jlesage/firefox:v25.03.1055c28defe31
openssl@3.3.2-r5
3.3.7-r0
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
openssl@3.5.4-r0
3.5.6-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.