StackRadar

CVE-2026-28388

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,342
of 17,805 indexed, latest versions
Container images
2,595
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28388 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,342 of 17,805 indexed charts deploy, on 2,595 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+98 more1.0.1f-1ubuntu2.27+esm13, 1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3+5 more1,686
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0906
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm420
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28388CGA-2c5c-rx22-cxxfCGA-92mm-ffw5-fq49DEBIAN-CVE-2026-28388UBUNTU-CVE-2026-28388AZL-81953ECHO-4471-00bd-faf3
Also known as
CGA-j9vv-xrrm-g5v2, CGA-xx8c-47rc-27jj, USN-8155-1, USN-8155-2

Charts affected

2,342 by stars
ChartLatestAffected imagesRadar Score
pagespages-nivesh1.0.02 of 3See more

pages pages-nivesh 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespagessandeepgudu1.0.02 of 3See more

pages pagessandeepgudu 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-shubhanker1.0.02 of 3See more

pages pages-shubhanker 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-ssharma09091.0.02 of 3See more

pages pages-ssharma0909 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-sucharitha1.0.02 of 3See more

pages pages-sucharitha 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-sudhir1.0.02 of 3See more

pages pages-sudhir 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-sushi1.0.02 of 3See more

pages pages-sushi 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-vasanth58141.0.02 of 3See more

pages pages-vasanth5814 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
pagespages-vjp1.0.02 of 3See more

pages pages-vjp 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
radarr-testpanzer1119Verified publisher0.1.21 of 2See more

radarr-test panzer1119 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/radarr:6.0.4c8a55bd83672
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,283
parcaparca-rr0.1.01 of 2See more

parca parca-rr 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.24.23776500fde82
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

2,405
parcial-1parcial-1-chart1.0.03 of 5See more

parcial-1 parcial-1-chart 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
esteban1930/backend-1:1.31.01ebe075675de
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
esteban1930/frontend-1:1.8.0f9078279632c
openssl@3.5.1-r0
3.5.6-r0
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

3,887
istio-operatorparticuleio1.7.01 of 1See more

istio-operator particuleio 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
gcr.io/istio-testing/operator:latest8d4576f7b98f
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9

Open the chart page →

4,196
clickhousepascaliskeVerified publisher1.0.01 of 1See more

clickhouse pascaliske 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6.70-alpinecd450891db46
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

491
cloudflaredpascaliskeVerified publisher3.0.01 of 1See more

cloudflared pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/cloudflared:2025.9.19b4e856d18f6
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,071
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,423
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

4,877
linkdingpascaliskeVerified publisher3.0.01 of 1See more

linkding pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,917
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

960
vaultwardenpascaliskeVerified publisher2.0.01 of 1See more

vaultwarden pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/dani-garcia/vaultwarden:1.35.2d89a6d21e361
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,455
pagespawan-pages1.0.02 of 3See more

pages pawan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
stk-fluent-bit-loki-s3paxtecnologia0.2.12 of 6See more

stk-fluent-bit-loki-s3 paxtecnologia 0.2.1

2 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
library/memcached:1.6.39-alpinec8503d4491ed
openssl@3.5.4-r0
3.5.6-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

3,767
everest-db-namespacepercona1.13.01 of 1See more

everest-db-namespace percona 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

769
matomopetbattle11.0.12 of 2See more

matomo petbattle 11.0.1

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

11,208
pet-battle-nsffpetbattle0.0.21 of 4See more

pet-battle-nsff petbattle 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
tensorflow/serving:latest8a208c232297
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

3,887
clickhousepetersandor14.3.21 of 1See more

clickhouse petersandor 14.3.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.2.398745843b17f9
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

2,243
mariadbpetersandor15.2.51 of 1See more

mariadb petersandor 15.2.5

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bitnami/mariadb:11.7.216a7dae804fb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,947
memcachedpetersandor14.1.61 of 1See more

memcached petersandor 14.1.6

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bitnami/memcached:1.6.38dd8f2cba9a5b
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,433
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,515
redispetersandor15.2.21 of 1See more

redis petersandor 15.2.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bitnami/redis:7.4.24e65bf641805
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,786
pgcatpgcatVerified publisher0.2.51 of 1See more

pgcat pgcat 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,828
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23

Open the chart page →

3,315
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,831
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

8,308
phronetisphronetis0.1.272 of 2See more

phronetis phronetis 0.1.27

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
knspar/phronetis:0.1.4609499d2dc91a
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
knspar/phronetis-operator:0.1.60c4f0543ee58
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

16,444
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

92,533
picoclawpicoclawVerified publisher0.1.261 of 1See more

picoclaw picoclaw 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/mattn/picoclaw:latest517556c8b144
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,551
piepieVerified publisher0.11.11 of 1See more

pie pie 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pie:0.18.0aa467443e407
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,185
pagespighosh-pages1.0.02 of 3See more

pages pighosh-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
openssl@3.1.4-r2
3.3.7-r0

Open the chart page →

1,698
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

3,562
firehose-ethereumpinaxVerified publisher0.3.22 of 2See more

firehose-ethereum pinax 0.3.2

2 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

7,236
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,477
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

58,368
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

58,309
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

5,000
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

12,063
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

7,633
planectlplanectlVerified publisher0.7.06 of 10See more

planectl planectl 0.7.0

6 of the 10 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
openssl@3.3.1-r0
3.3.7-r0
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2
gitea/act_runner:0.2.11c57233403eff
openssl@3.3.2-r0
3.3.7-r0
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.7-r0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

26,457
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,338

Container images carrying it

2,595 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
openssl@3.3.0-r2
3.3.7-r0
1
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/open-telemetry/demo:3.1.0-addfd7a4697116
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/open-telemetry/demo:3.1.0-frontend-proxyfd4da88bfeaa
openssl@3.0.2-0ubuntu1.29
no fix listed
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
ghcr.io/open-webui/mcpo:git-39b4867f06525afac6b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
ghcr.io/parca-dev/parca:v0.24.23776500fde82
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
openssl@3.3.2-r1
3.3.7-r0
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
ghcr.io/pschichtel/keycloak-webhook-router:main285e226fe7f6
openssl@3.3.2-r1
3.3.7-r0
1
ghcr.io/pyrra-dev/pyrra:v0.8.10e02ef538ef0
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
openssl@3.3.2-r1
3.3.7-r0
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
openssl@3.3.2-r1
3.3.7-r0
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
openssl@3.3.2-r1
3.3.7-r0
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
openssl@3.0.9-1
3.0.19-1~deb12u2
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
openssl@3.5.5-r0
3.5.6-r0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.