StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,302
of 17,792 indexed, latest versions
Container images
2,563
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,302 of 17,792 indexed charts deploy, on 2,563 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,658
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,302 by stars
ChartLatestAffected imagesRadar Score
clickhousepetersandor14.3.21 of 1See more

clickhouse petersandor 14.3.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.2.398745843b17f9
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

2,229
mariadbpetersandor15.2.51 of 1See more

mariadb petersandor 15.2.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnami/mariadb:11.7.216a7dae804fb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,924
memcachedpetersandor14.1.61 of 1See more

memcached petersandor 14.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnami/memcached:1.6.38dd8f2cba9a5b
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,411
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,156
redispetersandor15.2.21 of 1See more

redis petersandor 15.2.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnami/redis:7.4.24e65bf641805
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,762
pgcatpgcatVerified publisher0.2.51 of 1See more

pgcat pgcat 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,805
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23

Open the chart page →

3,299
dummy-servicephanVerified publisher0.3.41 of 1See more

dummy-service phan 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
phan2410/dummy-service:0.0.89c6ed6de26ca
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,784
falcon-asgi-serverphanVerified publisher0.1.01 of 1See more

falcon-asgi-server phan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
phan2410/falcon-asgi-server:0.1.04a86d138832d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

8,261
phronetisphronetis0.1.272 of 2See more

phronetis phronetis 0.1.27

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
knspar/phronetis:0.1.4609499d2dc91a
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
knspar/phronetis-operator:0.1.60c4f0543ee58
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

16,357
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

22,165
picoclawpicoclawVerified publisher0.1.261 of 1See more

picoclaw picoclaw 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/mattn/picoclaw:latest517556c8b144
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,550
piepieVerified publisher0.11.11 of 1See more

pie pie 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pie:0.18.0aa467443e407
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,171
pagespighosh-pages1.0.02 of 3See more

pages pighosh-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,262
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
openssl@3.1.4-r2
3.3.7-r0

Open the chart page →

1,688
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

3,544
firehose-ethereumpinaxVerified publisher0.3.22 of 2See more

firehose-ethereum pinax 0.3.2

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

7,193
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,423
substreams-sink-kvpinaxVerified publisher0.0.41 of 1See more

substreams-sink-kv pinax 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,777
substreams-sink-nooppinaxVerified publisher0.0.31 of 1See more

substreams-sink-noop pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,722
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

4,971
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

12,009
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

7,632
planectlplanectlVerified publisher0.7.06 of 10See more

planectl planectl 0.7.0

6 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
openssl@3.3.1-r0
3.3.7-r0
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2
gitea/act_runner:0.2.11c57233403eff
openssl@3.3.2-r0
3.3.7-r0
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.7-r0
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

26,158
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,338
k8s-node-image9-1-24pnnl-miscscripts0.2.1492 of 2See more

k8s-node-image9-1-24 pnnl-miscscripts 0.2.149

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,492
k8s-node-image9-1-25pnnl-miscscripts0.2.1052 of 2See more

k8s-node-image9-1-25 pnnl-miscscripts 0.2.105

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,492
k8s-node-image9-1-26pnnl-miscscripts0.2.922 of 2See more

k8s-node-image9-1-26 pnnl-miscscripts 0.2.92

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,492
k8s-node-image9-1-27pnnl-miscscripts0.2.902 of 2See more

k8s-node-image9-1-27 pnnl-miscscripts 0.2.90

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,492
k8s-node-image9-1-28pnnl-miscscripts0.2.1022 of 2See more

k8s-node-image9-1-28 pnnl-miscscripts 0.2.102

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,492
k8s-node-image9-1-29pnnl-miscscripts0.2.642 of 2See more

k8s-node-image9-1-29 pnnl-miscscripts 0.2.64

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,492
k8s-node-image9-1-30pnnl-miscscripts0.2.561 of 2See more

k8s-node-image9-1-30 pnnl-miscscripts 0.2.56

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

620
k8s-node-image9-1-31pnnl-miscscripts0.2.271 of 2See more

k8s-node-image9-1-31 pnnl-miscscripts 0.2.27

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

620
k8s-oidc-discovery-providerpnnl-miscscripts0.1.22 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
curlimages/curl:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.6-r0
library/nginx:1.29.49dd288848f44
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

4,297
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

12,998
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

9,227
podscopepodscope0.2.31 of 1See more

podscope podscope 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,487
libretimepodzone-chartsVerified publisher0.4.12 of 9See more

libretime podzone-charts 0.4.1

2 of the 9 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
library/rabbitmq:3.12-alpine97907aceae0a
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

11,255
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,587
polyaxonpolyaxon2.16.41 of 5See more

polyaxon polyaxon 2.16.4

1 of the 5 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

14,334
quickwitportefaix-hub0.1.11 of 1See more

quickwit portefaix-hub 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.1d29332bdadcc
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,657
postgrespostgresVerified publisher0.1.11 of 1See more

postgres postgres 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/postgres:13.12ced3ba927f4c
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,951
keydbpozetron0.5.31 of 1See more

keydb pozetron 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pozetroninc/keydb:v6.0.1653ae64f29da8
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

7,025
Practica_4_helmpr04helm0.1.03 of 7See more

Practica_4_helm pr04helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

27,697
practica-helmpractica-helm0.1.03 of 7See more

practica-helm practica-helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.4-bionic3d0e6df9fd5b
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.6-r0
slagattollas/weatherservice-practica:latest68e7f56393fc
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

28,537
pagesprasanthi1.0.02 of 3See more

pages prasanthi 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,262
prefect-agentprefectVerified publisher2024.8.301638221 of 1See more

prefect-agent prefect 2024.8.30163822

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,534
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

3,328
trino-loadbalancerpresto-loadbalancer0.3.11 of 1See more

trino-loadbalancer presto-loadbalancer 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

2,358
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

8,233

Container images carrying it

2,563 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
hassroutyyoussef/orderservice:latest2fc3d1617928
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hassroutyyoussef/userservice:lateste0392e2b4a90
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
hasura/graphql-engine:v2.48.10f6c1c4b957d2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
haugene/transmission-openvpn:4.0059216cfae4b
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
haveagitgat/tdarr:2.00.181256348872ce
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hazegoodlife/haaze:milksite8d4c63169e14
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
headscale/headscale:0.25.1a7a8ae9616bb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
headscale/headscale:0.27.1cd37b3001857
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
headwindmdm/hmdm:0.1.93550b4840840
openssl@3.0.2-0ubuntu1.26
no fix listed
1
heartexlabs/label-studio:latestaa461572e8f9
openssl@3.5.5-r0
3.5.6-r0
1
hecrom/myweatherangularclient:1.3.11bb0372939c19
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
openssl@3.3.1-r3
3.3.7-r0
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
openssl@3.0.9-1
3.0.19-1~deb12u2
1
helmforge/fastmcp-server:0.2.061f759a1421f
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
1
hiversh/gateway:0.1.45839226cc6e41
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
openssl@3.0.9-1
3.0.19-1~deb12u2
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
openssl@3.0.9-1
3.0.19-1~deb12u2
1
hmediade/printserver:latest481a552c8e1c
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
1
hmediade/printserver-init:latest7f005eb6c718
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
openssl@3.3.3-r0
3.3.7-r0
1
housewrecker/gaps:latestf417dd0a7547
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
1
hugohg34/toposervice:0.0.2812a03b3f274
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
hyperglance/init:wildfly467ad8491bc3
openssl@3.0.2-0ubuntu1.23
no fix listed
1
hyperglance/init:postgres9fd5faf1fe80
openssl@3.0.2-0ubuntu1.23
no fix listed
1
hyperglance/init:apacheb2f8c6d52623
openssl@3.0.2-0ubuntu1.23
no fix listed
1
hyperglance/postgresql-v2:10.0.6dadc39b2f786
openssl@3.0.2-0ubuntu1.29
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
hyperledger/fabric-orderer:1.3.06ee1abcfd840
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
hyperledger/fabric-peer:1.3.06756c7c48234
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
openssl@1.0.2g-1ubuntu4.12
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm15
1
ibmcom/skydive:0.22.0395e60cc6e3d
openssl@1.1.0g-2ubuntu4.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
openssl@3.0.9-1
3.0.19-1~deb12u2
1
ilum/marquez-web:0.53.2716437a51a6c
openssl@3.5.4-r0
3.5.6-r0
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
infiniflow/infinity:v0.7.0992c87a68612
openssl@3.0.2-0ubuntu1.23
no fix listed
1
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
openssl@3.5.5-r0
3.5.6-r0
1
inseefrlab/shelly:cloudshell31f04ca7436b
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.