StackRadar

CVE-2026-28388

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,342
of 17,805 indexed, latest versions
Container images
2,595
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28388 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,342 of 17,805 indexed charts deploy, on 2,595 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+98 more1.0.1f-1ubuntu2.27+esm13, 1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3+5 more1,686
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0906
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm420
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28388CGA-2c5c-rx22-cxxfCGA-92mm-ffw5-fq49DEBIAN-CVE-2026-28388UBUNTU-CVE-2026-28388AZL-81953ECHO-4471-00bd-faf3
Also known as
CGA-j9vv-xrrm-g5v2, CGA-xx8c-47rc-27jj, USN-8155-1, USN-8155-2

Charts affected

2,342 by stars
ChartLatestAffected imagesRadar Score
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

13,680
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23

Open the chart page →

13,152
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

101,852
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

12,028
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

3,313
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,014
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e14 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

4 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-monitor-deployment:2.19.2-branch.hotfix-2.19.1.124125-665e7e1b696ac5022ab
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e14828aee2277c
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

16,591
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb4 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

4 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-monitor-deployment:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2faf1508c1d3
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb107c63336ab5
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

16,624
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f83 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

3 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.17.14-branch.testing.72707.921a5f8ff1641ac3f1b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.17.14-branch.testing.72707.921a5f899913052b72e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

14,849
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091144 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

4 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-monitor-deployment:2.20.6-branch.testing1.154030-9b09114738c77eb6f97
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.20.6-branch.testing1.154030-9b09114cf1d99bad89a
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

16,624
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4693 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

3 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.18.11-branch.testing2.88634-335d469d6790a97ad47
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d4694bd113093583
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.18.11-branch.testing2.88634-335d469902b98ad5327
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

14,392
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3413 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

3 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.18.12-branch.testing3.88744-f55b34181335b40696a
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.18.12-branch.testing3.88744-f55b3414bd113093583
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.18.12-branch.testing3.88744-f55b341771f872cfa63
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

14,392
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b24 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

4 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-monitor-deployment:2.20.2-branch.testing4.134160-9fad4b23c8fbe855665
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.20.2-branch.testing4.134160-9fad4b270f5167d1d4d
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

16,242
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef5 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

5 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-monitor-deployment:2.21.3-branch.testing5.219631-2153befcf72ad0f25fb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.21.3-branch.testing5.219631-2153bef06ecc7a66a40
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

15,842
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e4 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

4 of the 4 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.25.10-branch.testing6.645-b125c1e2dbc553ed87c
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.25.10-branch.testing6.645-b125c1edd9db6cbe9bb
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,283
ocean-network-clientspot1.1.61 of 1See more

ocean-network-client spot 1.1.6

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

51,180
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

66,163
envoy-proxysqream-chartsVerified publisher0.6.01 of 2See more

envoy-proxy sqream-charts 0.6.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.1e596fda6a0ce
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23

Open the chart page →

2,333
flowssqream-chartsVerified publisher0.6.21 of 3See more

flows sqream-charts 0.6.2

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
alpine/curl:8.7.1f0c1b7ca12f6
openssl@3.3.1-r0
3.3.7-r0

Open the chart page →

655
umbrellasqream-chartsVerified publisher0.1.811 of 18See more

umbrella sqream-charts 0.1.81

1 of the 18 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
alpine/curl:8.7.1f0c1b7ca12f6
openssl@3.3.1-r0
3.3.7-r0

Open the chart page →

655
squadsquadVerified publisher0.1.111 of 1See more

squad squad 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
cm2network/squad:latest8cba47f53df5
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

2,532
pagessrinipages1.0.02 of 3See more

pages srinipages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ncsa/checks:main0b738bbc8d70
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

69,027
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

20,381
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,998
lighthouse-validatorstakewise7.0.11 of 2See more

lighthouse-validator stakewise 7.0.1

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
sigp/lighthouse:v7.0.12cae720e9a35
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

2,043
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

1,261
nethermindstakewise2.8.21 of 3See more

nethermind stakewise 2.8.2

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
nethermind/nethermind:1.31.893e57917371a
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

2,100
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
sigp/lighthouse:v2.1.2ad501f02cfef
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,609
rethstakewise1.2.11 of 3See more

reth stakewise 1.2.1

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

2,039
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

7,035
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

3,245
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,507
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

4,358
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

14,627
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

13,937
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

13,678
pagesstephendillondell1.0.02 of 3See more

pages stephendillondell 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,279
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
openssl@3.3.6-r0
3.3.7-r0

Open the chart page →

1,876
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

66,712
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
headscale/headscale:0.27.1cd37b3001857
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

5,193
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

12,792
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

12,792
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,581
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

2,626
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

4,862
substra-frontendsubstraVerified publisher1.2.31 of 1See more

substra-frontend substra 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,033
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
openssl@3.3.1-r0
3.3.7-r0

Open the chart page →

1,596
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

13,546
3d-printing-cost-calculatorssudo-kraken-3d-printing-cost-calculatorsVerified publisher0.1.41 of 1See more

3d-printing-cost-calculators sudo-kraken-3d-printing-cost-calculators 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28388.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

2,720

Container images carrying it

2,595 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
openssl@3.5.0-r0
3.5.6-r0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
openssl@3.5.0-r0
3.5.6-r0
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
openssl@3.1.4-r2
3.3.7-r0
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
openssl@3.3.1-r0
3.3.7-r0
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/tale/headplane:0.6.39476cc5adb12
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/themesama/kubernetes-kustomize-patcher:latestb1bf0669e3a0
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
openssl@3.5.4-r0
3.5.6-r0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.