StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,296
of 17,792 indexed, latest versions
Container images
2,550
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,296 of 17,792 indexed charts deploy, on 2,550 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,650
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0897
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,296 by stars
ChartLatestAffected imagesRadar Score
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

12,942
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

38,902
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

12,626
sebaopencord1.0.05 of 17See more

seba opencord 1.0.0

5 of the 17 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
openssl@1.0.2g-1ubuntu4.9
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-cli:1.6.0c4e41e92f046
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-netconf:1.6.037f80524c207
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-ofagent:1.6.09ee8c1f4428c
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-voltha:1.6.0ff596b62de59
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

93,946
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
voltha/voltha-onos:5.1.8e038acb950d3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

41,101
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,051
opencost-lensopencost-lens1.0.01 of 2See more

opencost-lens opencost-lens 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,110
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

769
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

741
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,162
kafka-connectoropenfaas0.7.151 of 1See more

kafka-connector openfaas 0.7.15

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,164
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,071
pro-builderopenfaas0.6.131 of 2See more

pro-builder openfaas 0.6.13

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,745
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

777
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

767
kruise-gameopenkruise1.1.01 of 1See more

kruise-game openkruise 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

918
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,737
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,068
openlit-operatoropenlit0.2.21 of 1See more

openlit-operator openlit 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

858
openobserveopenobserve0.92.21 of 6See more

openobserve openobserve 0.92.2

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.23.064cb6c858e79
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,166
openpanelopenpanel0.9.02 of 6See more

openpanel openpanel 0.9.0

2 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
library/redis:7.2.5-alpine6aaf3f5e6bc8
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

3,465
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

7,866
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,113
voyager-gatewayopenshift2026.1.151 of 2See more

voyager-gateway openshift 2026.1.15

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,645
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

15,602
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

36,252
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,005
kubernetes-syncopslevelVerified publisher0.8.01 of 1See more

kubernetes-sync opslevel 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,739
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
replicated/replicated-sdk:1.0.0-beta.318751b4963250
openssl@3.3.2-r2
3.6.2-r0

Open the chart page →

5,658
hiveopstty0.1.92 of 4See more

hive opstty 0.1.9

2 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.7-r0
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,550
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

838
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,021
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.010 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

10 of the 40 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
chromadb/chroma:1.5.7fc8dc8e11fb2
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
library/postgres:17.5-alpine6567bca8d7bc
openssl@3.5.1-r0
3.5.6-r0
library/postgres:17.2-alpine7e5df973a748
openssl@3.3.2-r4
3.3.7-r0
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.7-r0
yetiplatform/bloomcheck:dev85683ddfccbb
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

72,547
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

5,418
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,812
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

3,670
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,327
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

2,342
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

4,041
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

12,440
ungatep2p-avs0.1.03 of 3See more

ungate p2p-avs 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

27,597
p4p40.1.04 of 7See more

p4 p4 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,702
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

19,728
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23

Open the chart page →

3,604
pagespages1.0.02 of 3See more

pages pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
pagespages-10.1.01 of 1See more

pages pages-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:1.04d2eb25b9225
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

10,437
pagespages101.0.02 of 3See more

pages pages10 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
pagespages1111.0.02 of 3See more

pages pages111 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
pagespages21.0.02 of 3See more

pages pages2 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
pagespages-alexchmielu1.0.02 of 3See more

pages pages-alexchmielu 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242

Container images carrying it

2,550 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/alloy:v1.14.0f50931848bd8
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
grafana/fluent-plugin-loki:latest8a3882e8c28b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
grafana/grafana:13.0.10f86bada30d6
openssl@3.5.5-r0
3.5.6-r0
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
openssl@3.5.5-r0
3.5.6-r0
1
grafana/grafana:12.2.22ebef928d7e5
openssl@3.5.4-r0
3.5.6-r0
1
grafana/grafana:12.2.135c41e0fd029
openssl@3.5.4-r0
3.5.6-r0
1
grafana/grafana:11.2.2-security-01464eac539793
openssl@3.3.2-r0
3.3.7-r0
1
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.7-r0
1
grafana/grafana:11.6.062d2b9d20a19
openssl@3.3.3-r0
3.3.7-r0
1
grafana/grafana:12.3.070d9599b186c
openssl@3.5.4-r0
3.5.6-r0
1
grafana/grafana:12.2.074144189b384
openssl@3.5.1-r0
3.5.6-r0
1
grafana/grafana:11.5.28b37a2f028f1
openssl@3.3.2-r1
3.3.7-r0
1
grafana/grafana:12.1.1a1701c218024
openssl@3.5.1-r0
3.5.6-r0
1
grafana/grafana:10.4.19a9043254ba16
openssl@3.3.3-r0
3.3.7-r0
1
grafana/grafana:12.0.2b5b59bfc7561
openssl@3.3.3-r0
3.3.7-r0
1
grafana/grafana:12.3.2ba93c9d192e5
openssl@3.5.4-r0
3.5.6-r0
1
grafana/grafana:11.3.1fa801ab6e1ae
openssl@3.3.2-r0
3.3.7-r0
1
grafana/loki:2.9.1035b02acc6765
openssl@3.3.1-r3
3.3.7-r0
1
grafana/oncall:v1.16.5499851658393
openssl@3.3.4-r0
3.3.7-r0
1
grafana/promtail:3.5.165bfae480b57
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
grafana/promtail:3.6.18dcfdf466da0
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
grafana/tempo:2.6.0f55a8a1937ff
openssl@3.3.1-r3
3.3.7-r0
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
graylog/graylog:6.1.1019de1aff48c2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
gresearch/armada-executor:latest393aff4aa8f2
openssl@3.3.3-r0
3.3.7-r0
1
gresearch/armada-lookout:latestf5e3226f1d33
openssl@3.3.3-r0
3.3.7-r0
1
gresearch/armada-lookout-ingester:latest3df14cda1855
openssl@3.3.3-r0
3.3.7-r0
1
gresearch/armada-scheduler:latest6141a6213fcb
openssl@3.3.3-r0
3.3.7-r0
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
openssl@3.5.4-r0
3.5.6-r0
1
gridgain/community:8.9.11d32d182a0e6a
openssl@3.3.2-r0
3.3.7-r0
1
gridgain/gridgain9:9.1.1895018390077b
openssl@3.5.5-r0
3.5.6-r0
1
grpl/grapple-cli:0.2.127c00aafee6629
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
1
guacamole/guacamole:1.5.50f62f6d17ab3
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
gulacedia/web-dvwa-new:v367b467d961ca
openssl@3.0.9-1
3.0.19-1~deb12u2
1
hamidyousefi93/saam-test:latestc34f071f6ed0
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
openssl@3.3.2-r0
3.3.7-r0
1
hamzaarshad10/querypodpy:1.7154f38e8668e
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
hansehe/locust:1.1.0bc8e45262bc4
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hashicorp/boundary:0.21.037bf86488b74
openssl@3.3.5-r0
3.3.7-r0
1
hashicorp/terraform:1.9.7b77efab1a448
openssl@3.3.2-r0
3.3.7-r0
1
hashicorp/vault:1.19.0bbb7f98dc67d
openssl@3.3.3-r0
3.3.7-r0
1
hashicorp/vault-k8s:1.6.2103a2d817a74
openssl@3.3.3-r0
3.3.7-r0
1
hashicorp/vault-k8s:1.7.2ae3d307658b7
openssl@3.5.4-r0
3.5.6-r0
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hassroutyyoussef/orderservice:latest2fc3d1617928
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hassroutyyoussef/userservice:lateste0392e2b4a90
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
hasura/graphql-engine:v2.48.10f6c1c4b957d2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.