StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,298
of 17,803 indexed, latest versions
Container images
2,560
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,298 of 17,803 indexed charts deploy, on 2,560 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,657
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0900
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,298 by stars
ChartLatestAffected imagesRadar Score
flaskDiaryptj-miniproject2.1.21 of 2See more

flaskDiary ptj-miniproject 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
freedom98/flask:k3.0d7ce1533f297
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,114
pumperlypumperlyVerified publisher0.1.22 of 3See more

pumperly pumperly 0.1.2

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
openssl@3.5.5-r0
3.5.6-r0
postgis/postgis:17-3.4-alpine5a1dbedac34e
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

2,856
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

14,648
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

12,676
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

12,676
unifiqaoruVerified publisher1.1.31 of 2See more

unifi qaoru 1.1.3

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:7.0-jammy84c4a18b60a0
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

3,487
qualys-caqualys-ca-helm3.1.01 of 1See more

qualys-ca qualys-ca-helm 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
nelssec/qualys-agent-bootstrapper:v2.1.05e471f0cdeaa
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23

Open the chart page →

1,931
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

7,847
rabbitmq-stomprabbitmq-stompVerified publisher0.1.11 of 1See more

rabbitmq-stomp rabbitmq-stomp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
spy86/rabbitmq-stomp:latestea649101b9fb
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

3,047
rabbitpingrabbitping1.3.01 of 1See more

rabbitping rabbitping 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
udhos/rabbitping:1.3.0474c467bbf42
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,148
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,454
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

21,370
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,094
app-config-frontendradar-baseVerified publisher2.4.11 of 1See more

app-config-frontend radar-base 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config-frontend:0.6.2c5f1e2ca5781
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

807
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,476
data-dashboard-backendradar-baseVerified publisher0.6.21 of 1See more

data-dashboard-backend radar-base 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,077
kubecostradar-baseVerified publisher1.0.04 of 7See more

kubecost radar-base 1.0.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
openssl@3.3.2-r0
3.3.7-r0
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
openssl@3.4.1-r0
3.6.2-r0
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
openssl@3.3.2-r0
3.6.2-r0
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

9,625
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,341
radar-grafanaradar-baseVerified publisher0.1.41 of 2See more

radar-grafana radar-base 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
grafana/grafana:11.6.062d2b9d20a19
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,836
radar-homeradar-baseVerified publisher0.5.51 of 1See more

radar-home radar-base 0.5.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-home/radar-home:0.1.71cfe3da9d812
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

807
radar-hydraradar-baseVerified publisher0.3.42 of 2See more

radar-hydra radar-base 0.3.4

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.6-r0
oryd/hydra:v2.3.0b94007e19a1f
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

2,196
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

2,913
radar-kratosradar-baseVerified publisher0.1.51 of 1See more

radar-kratos radar-base 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

1,578
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,523
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

3,077
radar-rest-sources-authorizerradar-baseVerified publisher2.3.41 of 1See more

radar-rest-sources-authorizer radar-base 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-rest-source-auth/radar-rest-source-authorizer:4.4.153e096497f7db
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

807
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,509
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

2,591
radar-upload-connect-frontendradar-baseVerified publisher0.8.11 of 1See more

radar-upload-connect-frontend radar-base 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,084
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

2,796
pagesranjinigogga1.0.02 of 3See more

pages ranjinigogga 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,261
rdfoxrdfox-helm-chart0.1.22 of 2See more

rdfox rdfox-helm-chart 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
oxfordsemantic/rdfox:5.6db17910eb855
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
oxfordsemantic/rdfox-init:5.6baf570ff968d
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

12,910
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,613
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,862
sqpreadyset-sqp-nightly0.1.0-nightly.202604302 of 3See more

sqp readyset-sqp-nightly 0.1.0-nightly.20260430

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
readysettech/sqp:latest588f3507280e
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
readysettech/sqp-duckdb:latest67a83203ce60
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

3,548
pagesrebecca-pages1.0.02 of 3See more

pages rebecca-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,261
recipe-apprecipe-app0.1.02 of 2See more

recipe-app recipe-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
openssl@3.3.3-r0
3.3.7-r0
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

3,568
helm-redchefredchef0.1.02 of 3See more

helm-redchef redchef 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
sharanalwar/redchef-backend:latest8d3cab80df49
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
sharanalwar/redchef-frontend:latest5e82950b16b7
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

4,956
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

4,258
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,296
relfinder-reformedrelfinderreformed2.0.02 of 2See more

relfinder-reformed relfinderreformed 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
openssl@3.3.1-r0
3.3.7-r0
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

6,356
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

7,469
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,981
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

7,160
claude-relayrevolution10.1.372 of 4See more

claude-relay revolution1 0.1.37

2 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

4,808
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,896
bookinforgnu1.0.03 of 7See more

bookinfo rgnu 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

20,539
httpbinrgnu1.0.01 of 1See more

httpbin rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
citizenstig/httpbin:latestb81c818ccb86
openssl@1.0.2g-1ubuntu4.5
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

11,458
istio-bookinforgnu1.0.23 of 7See more

istio-bookinfo rgnu 1.0.2

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

20,539
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
istio/examples-helloworld-v2:latest0a7f02b2c7c9
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,504

Container images carrying it

2,560 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
openebs/lvm-driver:1.10.141f73aba7f31
openssl@3.5.1-r0
3.5.6-r0
1
openelevation/open-elevation:latest82fb21612e86
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3
1
openkm/openkm-ce:6.3.113bc465a7461b
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
openssl@3.3.3-r0
3.3.7-r0
1
openkruise/kruise-manager:v1.8.30482722b4e56
openssl@3.3.6-r0
3.3.7-r0
1
openmined/syft-backend:0.9.5b72f74a68b32
openssl@3.4.1-r0
3.6.2-r0
1
openmined/syft-frontend:0.9.5d11524a3854a
openssl@3.4.1-r0
3.6.2-r0
1
opennode/waldur-site-agent:1.0.76d2e3b97c8d2
openssl@3.3.2-r1
3.3.7-r0
1
openproject/hocuspocus:release-338001b288dc1359dfb5
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm3
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm3
1
openthread/otbr:latestf307f59f6432
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
openvino/model_server:2025.2.11e7cd1d70cc1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.6-r0
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.7-r0
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
openssl@3.3.3-r0
3.3.7-r0
1
oryd/hydra:v2.3.0b94007e19a1f
openssl@3.3.2-r1
3.3.7-r0
1
oryd/hydra:v26.2.0ff67c7fb5f95
openssl@3.3.6-r0
3.3.7-r0
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
openssl@3.3.3-r0
3.3.7-r0
1
oryd/keto:v26.2.0bfdb8b9e283a
openssl@3.3.6-r0
3.3.7-r0
1
oryd/kratos:v26.2.02a13bb8d362c
openssl@3.3.6-r0
3.3.7-r0
1
oryd/oathkeeper:v26.2.0467329abde34
openssl@3.3.6-r0
3.3.7-r0
1
outlinewiki/outline:0.82.0494dfb9249a6
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
owncloud/ocis:7.1.388e7c854517d
openssl@3.3.3-r0
3.3.7-r0
1
owncloud/ocis:8.0.1b38fd8fdd58f
openssl@3.5.5-r0
3.5.6-r0
1
owncloud/server:10.15.051d9b74fc2a8
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
owncloud/server:10.16.274c53d341076
openssl@3.0.2-0ubuntu1.23
no fix listed
1
owncloud/server:10.16.3b3f9efdcd7f7
openssl@3.0.2-0ubuntu1.25
no fix listed
1
oxfordsemantic/rdfox:5.6db17910eb855
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
pangeo/base-notebook:2024.01.155fbe688a4f80
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
payara/micro:7.2026.2-jdk25fb44b8ce1cb2
openssl@3.3.6-r0
3.3.7-r0
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
1
penpotapp/backend:2.2.147853d9bb9dd
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
penpotapp/exporter:2.2.15c835ffd87ab
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
phan2410/dummy-service:0.0.89c6ed6de26ca
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
photoprism/photoprism:220629-jammy2954334adbda
openssl@3.0.2-0ubuntu1.5
3.0.2-0ubuntu1.23
1
photoprism/photoprism:251130db16ee6b1ba3
openssl@3.5.3-1ubuntu2
3.5.3-1ubuntu3.3
1
photoprism/photoprism:240711-cefc6fd632ca74
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.6-r0
1
phpipam/phpipam-cron:v1.7.354468713454e
openssl@3.3.2-r1
3.3.7-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
openssl@3.3.2-r1
3.3.7-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
openssl@3.5.1-1
3.5.5-1~deb13u2
1
pk910/powfaucet:v2-stable3dcae6a62896
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
platform9community/admin-server:latestde3fa9b70df1
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.