StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,303
of 17,790 indexed, latest versions
Container images
2,568
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,303 of 17,790 indexed charts deploy, on 2,568 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,663
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,303 by stars
ChartLatestAffected imagesRadar Score
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

12,150
homerlmatfyVerified publisher0.1.11 of 1See more

homer lmatfy 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
b4bz/homer:v25.02.2c367265313f9
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

345
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,392
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

2,162
tempo-distributedloafoe1.20.12 of 2See more

tempo-distributed loafoe 1.20.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
openssl@3.3.1-r3
3.3.7-r0
library/memcached:1.6.29-alpine462ae4a35c26
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

2,027
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

947
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

7,534
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,518
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

9,062
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23

Open the chart page →

6,680
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,578
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

23,689
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

5,913
loxilbloxilbVerified publisher0.1.02 of 2See more

loxilb loxilb 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
openssl@3.0.2-0ubuntu1.26
no fix listed
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

4,513
lsdisklsdiskVerified publisher2.0.71 of 4See more

lsdisk lsdisk 2.0.7

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

5,074
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

17,858
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
elastictranscoder/media-storage:f6d861a026208b8c2359
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
elastictranscoder/transcoder:627e21dcb4a0327029e6
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

58,245
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,009
hyperglassm0nsterrr-hyperglassVerified publisher4.2.12 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

4,669
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,805
magistralamagistrala-devopsVerified publisher0.16.25 of 42See more

magistrala magistrala-devops 0.16.2

5 of the 42 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31-latestcaa5b411be16
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
library/nats:2.10.17-alpineb7752304692b
openssl@3.3.1-r0
3.3.7-r0
natsio/nats-server-config-reloader:0.15.05b21830a9e9d
openssl@3.3.0-r2
3.3.7-r0
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

24,537
docker-mailservermailserverVerified publisher0.2.657 of 9See more

docker-mailserver mailserver 0.2.65

7 of the 9 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
jeboehm/mailserver-filter:5.0.92e756949e537d
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-mta:5.0.925fb2f31c940d
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-web:5.0.929da13edf5aa8
openssl@3.5.2-r0
3.5.6-r0
mvance/unbound:1.22.076906da36d18
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

10,921
mangadev-hello-worldmangadev0.3.01 of 1See more

mangadev-hello-world mangadev 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
wagnermanganelli164/webserver-hello-world:0.3.0d4ef27a4f180
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

863
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

7,334
eirmargaysVerified publisher1.7.21 of 1See more

eir margays 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
margays/eir:v1.7.22883fdd06fd7
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

812
marge-botmarge-bot-helm1.3.51 of 1See more

marge-bot marge-bot-helm 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,597
consumermarthydavidVerified publisher0.1.61 of 1See more

consumer marthydavid 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

806
producermarthydavidVerified publisher0.1.61 of 1See more

producer marthydavid 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

806
circleci-runnermatic-insurance0.1.11 of 1See more

circleci-runner matic-insurance 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
circleci/runner:launch-agent9bdc62f02162
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

4,152
kruisematrixone-operatorVerified publisher1.8.31 of 2See more

kruise matrixone-operator 1.8.3

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
openkruise/kruise-manager:v1.8.30482722b4e56
openssl@3.3.6-r0
3.3.7-r0

Open the chart page →

1,775
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,113
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

8,409
mayastormayastorVerified publisher2.12.12 of 31See more

mayastor mayastor 2.12.1

2 of the 31 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

21,269
eoloplantmca-eoloplaner0.1.03 of 7See more

eoloplant mca-eoloplaner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

29,746
backstagemcwarmanVerified publisher0.10.102 of 2See more

backstage mcwarman 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

9,765
mdai-hubmdai-hubVerified publisher0.10.11 of 14See more

mdai-hub mdai-hub 0.10.1

1 of the 14 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

4,818
applicationmediamarktsaturn1.37.01 of 1See more

application mediamarktsaturn 1.37.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quay.io/heubeck/examiner:1.14.61154472ff8c4
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

812
tinymediamanagermedia-servarrVerified publisher1.6.21 of 2See more

tinymediamanager media-servarr 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

8,147
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

18,730
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

3,716
msmmedia-streaming-meshVerified publisher0.1.175 of 6See more

msm media-streaming-mesh 0.1.17

5 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9

Open the chart page →

11,528
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

18,730
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

18,730
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,886
memgptmemgptVerified publisher0.3.191 of 2See more

memgpt memgpt 0.3.19

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ankane/pgvector:v0.5.1d3a9d8ac27bb
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,883
istiomesosphere1.25.11 of 2See more

istio mesosphere 1.25.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,455
istio-helm-cnimesosphere1.25.11 of 1See more

istio-helm-cni mesosphere 1.25.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/install-cni:1.29.0ce27c9ce43c8
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,584
istio-helm-istiodmesosphere1.25.12 of 2See more

istio-helm-istiod mesosphere 1.25.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/pilot:1.29.0325156535773
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
mesosphere/kubectl:v1.35.0-alpineea01a9387771
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

3,829
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
openssl@1.1.1f-1ubuntu2
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

12,052
kube-prometheus-stackmesosphere87.16.01 of 7See more

kube-prometheus-stack mesosphere 87.16.0

1 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

7,452

Container images carrying it

2,568 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
frankescobar/allure-docker-service:2.21.08a4d7e9308de
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1
free5gmano/nextepc-mongodb:latest36f806935519
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
1
freedom98/flask:k3.0d7ce1533f297
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
galaxy/cloudman-server:lateste5c265fe9fcd
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
gchq/accumulo:2.0.1c460bb587d6d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.6-r0
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.6-r0
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
openssl@3.0.2-0ubuntu1.23
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
gethue/hue:4.11.011b649636e68
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
gethue/hue:4.10.05702b2c37ff9
nodejs@14.17.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.9
openssl1.0@1.0.2n-1ubuntu5.6
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
gethue/hue:latest7d5c1b9f8a79
nodejs@24.13.1-1nodesource1
openssl@3.0.2-0ubuntu1.19
no fix listed
3.0.2-0ubuntu1.23
1
getmeili/meilisearch:v1.11.0b9be3d2d4251
openssl@3.3.2-r0
3.3.7-r0
1
getmeili/meilisearch:v1.13.3bed3fb650e62
openssl@3.3.3-r0
3.3.7-r0
1
getmeili/meilisearch:v1.30.0f3ecbc8c5bfb
openssl@3.5.4-r0
3.5.6-r0
1
getsentry/relay:24.10.0ba7bf9163219
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
giantswarm/silence-operator:0.13.0a6cac55aa2d4
openssl@3.3.3-r0
3.3.7-r0
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
openssl@3.3.2-r0
3.3.7-r0
1
gitea/act_runner:0.3.1c2a169c5e998
openssl@3.5.5-r0
3.5.6-r0
1
gitea/act_runner:0.2.11c57233403eff
openssl@3.3.2-r0
3.3.7-r0
1
gitea/gitea:1.22.376f516a1a8c2
openssl@3.3.2-r0
3.3.7-r0
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
glanceapp/glance:v0.8.46df86a7e8868
openssl@3.3.3-r0
3.3.7-r0
1
glasskube/operator:0.12.2be5133100d63
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
glenndehaan/kube-hook:latest0a7116f48bfe
openssl@3.3.2-r0
3.3.7-r0
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
goccx/go-file-server:latestf4b3ebea0303
openssl@3.3.5-r0
3.3.7-r0
1
goccx/go-file-server-ui:latest784b35910d52
openssl@3.3.2-r0
3.3.7-r0
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
openssl@3.0.9-1
3.0.19-1~deb12u2
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
openssl@3.0.9-1
3.0.19-1~deb12u2
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
openssl@3.0.9-1
3.0.19-1~deb12u2
1
gotenberg/gotenberg:8.30206a6c708fc6
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
gotson/komga:0.99.49b15ea6bfc30
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
openssl@3.6.0-r4
3.6.2-r0
1
gradiant/open5gs-dbctl:0.10.3332031245fce
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
gradle/build-cache-node:21.25bacbee677a9
openssl@3.3.3-r0
3.3.7-r0
1
grafana/agent:v0.44.23364714a2f64
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
grafana/alloy:v1.5.101a63f4e032c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.