StackRadar

CVE-2026-28388

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,309
of 17,790 indexed, latest versions
Container images
2,575
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28388 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,309 of 17,790 indexed charts deploy, on 2,575 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+98 more1.0.1f-1ubuntu2.27+esm13, 1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3+5 more1,670
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28388CGA-2c5c-rx22-cxxfCGA-92mm-ffw5-fq49DEBIAN-CVE-2026-28388UBUNTU-CVE-2026-28388AZL-81953ECHO-4471-00bd-faf3
Also known as
CGA-j9vv-xrrm-g5v2, CGA-xx8c-47rc-27jj, USN-8155-1, USN-8155-2

Charts affected

2,309 by stars
ChartLatestAffected imagesRadar Score
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

9,411
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

13,369
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

10,127
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23

Open the chart page →

18,357
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,985
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

5,371
smartorchestratorassist-iot-smart-orchestrator4.0.05 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

5 of the 14 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssl@3.0.9-1
3.0.19-1~deb12u2
devopsfaith/krakend:latestf8bdaa8a1a43
openssl@3.3.3-r0
3.3.7-r0
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

45,656
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

14,013
account-monitorastria0.0.11 of 1See more

account-monitor astria 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,952
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

32,638
auctioneerastria0.0.21 of 1See more

auctioneer astria 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,201
celestia-localastria9.0.02 of 2See more

celestia-local astria 9.0.0

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.6-r0
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

3,299
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

1,513
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,177
evm-rollupastria4.1.02 of 2See more

evm-rollup astria 4.1.0

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.6-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,010
evm-stackastria5.0.32 of 2See more

evm-stack astria 5.0.3

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.6-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,010
flame-rollupastria0.1.32 of 2See more

flame-rollup astria 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

3,710
hermesastria0.7.11 of 1See more

hermes astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

1,996
hyperlane-agentsastria0.1.41 of 2See more

hyperlane-agents astria 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23

Open the chart page →

2,540
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
openssl@3.3.2-r4
3.3.7-r0
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

6,335
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,320
sequencer-relayerastria2.0.01 of 1See more

sequencer-relayer astria 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,952
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,429
attestkeepattestkeepVerified publisher1.1.01 of 2See more

attestkeep attestkeep 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
library/postgres:16.4-alpine5660c2cbfea5
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

1,598
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

6,958
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

6,321
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
kuzwolka/aws9:news3e8880fbbb96
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
kuzwolka/aws9:blog4a7707410bf1
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
kuzwolka/aws9:shop84a9d9766345
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

18,436
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

3,310
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
openssl@3.0.2-0ubuntu1.23
no fix listed

Open the chart page →

5,894
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,760
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

6,321
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

20,794
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

4,059
qbittorrent-vpnbdclark-helm-chartsVerified publisher0.7.61 of 2See more

qbittorrent-vpn bdclark-helm-charts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.41.11a5bf4b4820a
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,010
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,137
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
behnambm/docker-sample:v1bd3ad88afff9
openssl@3.3.1-r0
3.3.7-r0

Open the chart page →

2,750
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

7,246
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

5,117
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

8,029
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
nodejs@14.17.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.9
openssl1.0@1.0.2n-1ubuntu5.6
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

22,929
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,336
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,225
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

13,517
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,302
istio-bookinfobookinfo1.2.23 of 6See more

istio-bookinfo bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

19,006
colosseumbook-k8sinfra-v21.0.184 of 5See more

colosseum book-k8sinfra-v2 1.0.18

4 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
openssl@3.0.2-0ubuntu1.25
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
sysnet4admin/colosseum-prm:log5802bfcd7fed
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
sysnet4admin/colosseum-rwd:log74ded2d92f07
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

27,215
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,289
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,808
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
library/cassandra:3.11.65aa8400b4b3b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

19,311

Container images carrying it

2,575 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ixsystems/truecommand:3.2.019c218455cd2
openssl@3.5.1-1
3.5.5-1~deb13u2
1
jacobalberty/unifi:v7.1.664a3616625dda
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8
1
jacobalberty/unifi:5.10.19c409924e2463
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
1
jaedb/iris:latest048cfbf58d57
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jaegertracing/jaeger:2.9.0e128b9adbb29
openssl@3.5.1-r0
3.5.6-r0
1
jakowenko/double-take:1.6.0b858bac9e32a
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
openssl@3.3.2-r0
3.3.7-r0
1
janzo83/serviceexample:latestfb3c4ac36f3e
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
jeboehm/mailserver-filter:5.0.92e756949e537d
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-mta:5.0.925fb2f31c940d
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
openssl@3.3.4-r0
3.3.7-r0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
openssl@3.5.2-r0
3.5.6-r0
1
jedi132000/nextapp:latestdc2a81e92f23
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
jellyfin/jellyfin:10.11.81694ff069f0c
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
jellyfin/jellyfin:10.11.717285f9cce63
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
jellyfin/jellyfin:10.10.317c3a8d9dddb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jellyfin/jellyfin:10.11.6333b64771663
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
jellyfin/jellyfin:10.9.1079fb3d73a3e9
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
jellyfin/jellyfin:10.10.77ae36aab93ef
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jellyfin/jellyfin:10.10.696b09723b22f
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
jhaals/yopass:11.17.026873480863b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
jhaals/yopass:12.5.0916a1cf45d36
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
openssl@3.3.2-r0
3.3.7-r0
1
jhipster/jhipster-registry:latest7184525acd4d
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
1
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm3
1
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jkroepke/github_exporter:1.8.03d850992786d
openssl@3.5.4-r0
3.5.6-r0
1
jlesage/firefox:v25.03.1055c28defe31
openssl@3.3.2-r5
3.3.7-r0
1
jmferrer/azure-devops-agent:latest030f68ec6998
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
openssl@3.5.4-r0
3.5.6-r0
1
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
openssl@3.0.2-0ubuntu1.15
no fix listed
3.0.2-0ubuntu1.23
1
joxit/docker-registry-ui:2.6.0bb5956a6b378
openssl@3.5.4-r0
3.5.6-r0
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
openssl@1.1.1f-1ubuntu2
1.1.1f-1ubuntu2.24+esm3
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
openssl@3.3.2-r1
3.3.7-r0
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
openssl@3.3.1-r3
3.3.7-r0
1
kayrosuno/kping:latestf3bd44b29b0d
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
openssl@3.5.5-r0
3.5.6-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.