StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,302
of 17,792 indexed, latest versions
Container images
2,563
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,302 of 17,792 indexed charts deploy, on 2,563 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,658
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,302 by stars
ChartLatestAffected imagesRadar Score
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
woojoong/wowza:latestec230db19652
openssl@1.1.0g-2ubuntu4.1
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

42,879
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

29,359
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
openssl@1.1.0g-2ubuntu4.1
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

15,684
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
openssl@1.1.1-1ubuntu2.1~18.04.9
openssl1.0@1.0.2n-1ubuntu5.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

14,574
omec-control-planeopencord0.1.314 of 8See more

omec-control-plane opencord 0.1.31

4 of the 8 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm15
omecproject/c3po-hssdb:master-latest28a90cc26716
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3
omecproject/mme-exporter:paging-latestbcc5f19fd676
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
omecproject/openmme:master-latest64776cb9edb3
openssl@1.0.2g-1ubuntu4.17
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

40,941
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

12,953
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

38,966
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

12,646
sebaopencord1.0.05 of 17See more

seba opencord 1.0.0

5 of the 17 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
openssl@1.0.2g-1ubuntu4.9
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-cli:1.6.0c4e41e92f046
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-netconf:1.6.037f80524c207
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-ofagent:1.6.09ee8c1f4428c
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-voltha:1.6.0ff596b62de59
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

94,117
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
voltha/voltha-onos:5.1.8e038acb950d3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

41,148
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,064
opencost-lensopencost-lens1.0.01 of 2See more

opencost-lens opencost-lens 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,113
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

769
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

741
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,162
kafka-connectoropenfaas0.7.151 of 1See more

kafka-connector openfaas 0.7.15

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,164
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,071
pro-builderopenfaas0.6.131 of 2See more

pro-builder openfaas 0.6.13

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,739
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

777
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

767
kruise-gameopenkruise1.1.01 of 1See more

kruise-game openkruise 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

918
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,744
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,083
openlit-operatoropenlit0.2.21 of 1See more

openlit-operator openlit 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

858
openobserveopenobserve0.92.21 of 6See more

openobserve openobserve 0.92.2

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.23.064cb6c858e79
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,159
openpanelopenpanel0.9.02 of 6See more

openpanel openpanel 0.9.0

2 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
library/redis:7.2.5-alpine6aaf3f5e6bc8
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

3,472
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

7,889
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,121
voyager-gatewayopenshift2026.1.151 of 2See more

voyager-gateway openshift 2026.1.15

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,659
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

15,622
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

36,335
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,006
kubernetes-syncopslevelVerified publisher0.8.01 of 1See more

kubernetes-sync opslevel 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,747
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
replicated/replicated-sdk:1.0.0-beta.318751b4963250
openssl@3.3.2-r2
3.6.2-r0

Open the chart page →

5,658
hiveopstty0.1.92 of 4See more

hive opstty 0.1.9

2 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.7-r0
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,569
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

840
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,020
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.010 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

10 of the 40 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
chromadb/chroma:1.5.7fc8dc8e11fb2
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
library/postgres:17.5-alpine6567bca8d7bc
openssl@3.5.1-r0
3.5.6-r0
library/postgres:17.2-alpine7e5df973a748
openssl@3.3.2-r4
3.3.7-r0
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.7-r0
yetiplatform/bloomcheck:dev85683ddfccbb
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

72,857
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

5,418
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,814
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

3,679
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,335
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

2,351
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

4,052
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

12,426
ungatep2p-avs0.1.03 of 3See more

ungate p2p-avs 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23

Open the chart page →

27,579
p4p40.1.04 of 7See more

p4 p4 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,784
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

19,739
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23

Open the chart page →

3,612
pagespages1.0.02 of 3See more

pages pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,262

Container images carrying it

2,563 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
instill/artifact-backend:b28766ac4a393e601ed
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
1
instill/console:0.68.54cd70e2df5c6
openssl@3.5.1-r0
3.5.6-r0
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
1
instill/model-backend:611f0f2e980125e5ba5
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
instructure/kinesalite:latest34400d82f28f
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
1
instrumentisto/rsync-ssh:alpine6cbad37c2fbd
openssl@3.5.5-r0
3.5.6-r0
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
openssl@1.1.1f-1ubuntu2.15
1.1.1f-1ubuntu2.24+esm3
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
openssl@3.5.5-r0
3.5.6-r0
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
intelowlproject/intelowl_nginx:v6.6.12f01e79b8064
openssl@3.5.4-r0
3.5.6-r0
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3
1
iofog/router:2.0.17260cf861479
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1
iomesh/csi-driver:v2.8.01a151f602451
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
iomesh/deck:v0.2.0282d6c419ed3
openssl@3.3.1-r3
3.3.7-r0
1
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
openssl@3.3.1-r3
3.3.7-r0
1
iomesh/node-disk-manager:1.8.0-2292ad270082e
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ispras/svacer:11-2-042aa9fa9f189
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
istio/examples-helloworld-v1:latest328b237e4fb1
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
istio/examples-helloworld-v2:latest0a7f02b2c7c9
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
istio/install-cni:1.10.32232f365aed6
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/install-cni:1.23.6ab34c4740f44
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
istio/install-cni:1.29.0ce27c9ce43c8
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
istio/node-agent-k8s:1.2.9268ab879ea51
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
istio/operator:1.10.3655eefa11c84
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/operator:1.12.06cfce8a071b9
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
istio/operator:1.18.270f9d1fe5fff
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
istio/pilot:1.10.0294ca55bd1cc
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/pilot:1.29.0325156535773
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
istio/pilot:1.23.69c3d6a218181
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
istio/pilot:1.16.0ac0284d75ec9
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
1
istio/pilot:1.2.9c09319753454
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
istio/pilot:1.17.1ce9d87606701
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
1
istio/pilot:1.15.2db08d6963975
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
1
istio/pilot:1.10.3e7e110a421c2
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/pilot:1.29.1f8b0e412ac4a
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
istio/proxyv2:1.2.90c78be035e98
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
istio/proxyv2:1.9.687a9db561d2e
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/proxyv2:1.10.088c6c693e67a
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
istio/proxyv2:1.14.1df69c1a7af7c
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm3
1
istio/ztunnel:1.25.005f3972d80a9
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ivanjosipovic/ingress-nginx-validate-jwt:1.13.995089339a68ae
openssl@3.3.3-r0
3.3.7-r0
1
ixsystems/truecommand:3.2.019c218455cd2
openssl@3.5.1-1
3.5.5-1~deb13u2
1
jacobalberty/unifi:v7.1.664a3616625dda
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.