StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,301
of 17,797 indexed, latest versions
Container images
2,563
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,301 of 17,797 indexed charts deploy, on 2,563 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,658
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,301 by stars
ChartLatestAffected imagesRadar Score
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,860
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
openssl@1.1.1-1ubuntu2.1~18.04.13
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

11,019
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,262
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,346
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,163
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,292
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

1,663
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,407
eggybyte-chaineggybyte-hcr1.0.01 of 1See more

eggybyte-chain eggybyte-hcr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

806
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

3,976
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

8,057
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
openssl@3.0.2-0ubuntu1.26
no fix listed
seafileltd/seafile-mc:9.0.106693911bcc40
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

25,285
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,971
redisemberstackVerified publisher1.0.211 of 1See more

redis emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/redis:8.0.2b43d2dcbbdb1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

1,996
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

10,618
kube-ecp-stackemqx-operator2.5.15 of 16See more

kube-ecp-stack emqx-operator 2.5.1

5 of the 16 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
datalayers/datalayers:v2.2.1017b292079239
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
openssl@3.3.2-r0
3.3.7-r0
emqx/ecp-ui:2.5.1e33e9816f147
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
emqxecp/otelcol:2.5.04c31d9bec846
openssl@3.3.2-r0
3.3.7-r0
library/telegraf:1.27507a3eecf809
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

23,844
enclaveenclave0.1.11 of 1See more

enclave enclave 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
enclavenetworks/enclave:latest0a99759300d1
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

2,750
kube-packetloss-exporterenixVerified publisher0.2.11 of 2See more

kube-packetloss-exporter enix 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,183
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/haproxy:2.9.6fc5748ff7c72
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,971
network-exporterenixVerified publisher0.3.01 of 1See more

network-exporter enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
syepes/network_exporter:1.8.000af1691570e
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,373
topomatikenixVerified publisher1.3.11 of 1See more

topomatik enix 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
openssl@3.0.2-0ubuntu1.23
no fix listed

Open the chart page →

2,161
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,160
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

7,330
eolicplantseolicplantsVerified publisher0.1.03 of 7See more

eolicplants eolicplants 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,416
eoloPlanteolo-plannerVerified publisher0.1.04 of 7See more

eoloPlant eolo-planner 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,784
eoloplannereoloplannerVerified publisher0.1.04 of 7See more

eoloplanner eoloplanner 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

32,456
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.04 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,784
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.03 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,382
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

28,588
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

27,237
eoloplanteoloplant1.0.04 of 7See more

eoloplant eoloplant 1.0.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,784
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

27,861
servereoloserverVerified publisher0.1.04 of 7See more

server eoloserver 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

32,456
flywayeosc-lot-1Verified publisher0.7.02 of 3See more

flyway eosc-lot-1 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alpine/git:v2.49.1c0280cf95723
openssl@3.5.4-r0
3.5.6-r0
flyway/flyway:9.1545b5d7cdc75a
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

9,460
mariadbeosc-lot-1Verified publisher0.2.01 of 2See more

mariadb eosc-lot-1 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,464
mariadb-backupeosc-lot-1Verified publisher0.5.01 of 2See more

mariadb-backup eosc-lot-1 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,464
mariadb-run-scripteosc-lot-1Verified publisher0.3.01 of 1See more

mariadb-run-script eosc-lot-1 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,464
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,385
postgresql-backupeosc-lot-1Verified publisher0.4.21 of 2See more

postgresql-backup eosc-lot-1 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine3.20468d34fefd63
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

1,467
rabbitmqeosc-lot-1Verified publisher0.3.01 of 2See more

rabbitmq eosc-lot-1 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

2,534
rediseosc-lot-1Verified publisher0.2.01 of 1See more

redis eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
redis/redis-stack-server:6.2.6-v251a58f32d412
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

3,111
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,900
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:12.2.2b1cb255a9939
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

6,587
benchmarkoor-apiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-api ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
openssl@3.3.6-r0
3.3.7-r0

Open the chart page →

901
benchmarkoor-uiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-ui ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,334
blutgangethereum-helm-chartsVerified publisher0.0.121 of 1See more

blutgang ethereum-helm-charts 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
makemake1337/blutgang:latest8a55174fc830
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,542
chaos-meshethereum-helm-chartsVerified publisher0.0.33 of 4See more

chaos-mesh ethereum-helm-charts 0.0.3

3 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/chaos-mesh/chaos-mesh:v2.8.0091b906a0b13
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

12,230
eth-faucetethereum-helm-chartsVerified publisher0.1.11 of 1See more

eth-faucet ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
chainflag/eth-faucet:latestac642796bcb6
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,996
powfaucetethereum-helm-chartsVerified publisher1.2.11 of 1See more

powfaucet ethereum-helm-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
pk910/powfaucet:v2-stable3dcae6a62896
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,497
rpc-proxyethereum-helm-chartsVerified publisher0.1.21 of 1See more

rpc-proxy ethereum-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/gochain/rpc-proxy/rpc-proxy:latestca01f5ab95f7
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,472

Container images carrying it

2,563 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
zimengxiong/excalidash-backend:0.4.271273af713c91
openssl@3.5.5-r0
3.5.6-r0
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
openssl@3.5.5-r0
3.5.6-r0
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed
1
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
openssl@1.1.1-1ubuntu2.1~18.04.5
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
openssl@1.0.2g-1ubuntu4.8
1.0.2g-1ubuntu4.20+esm15
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
openssl@1.0.2g-1ubuntu4.8
1.0.2g-1ubuntu4.20+esm15
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
openssl@3.4.1-r2
3.6.2-r0
1
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
openssl@3.4.1-r0
3.6.2-r0
1
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
openssl@3.3.2-r0
3.6.2-r0
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm15
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
gcr.io/ml-pipeline/viewer-crd-controller:2.3.08cf8213d69e4
openssl@3.3.1-r3
3.3.7-r0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/98jan/smalland-server/smalland-server:deveb7be822d5b2
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.9
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.9
1
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
openssl@3.0.2-0ubuntu1.25
no fix listed
1
ghcr.io/akpw/mktxp:1.2.17bd6f22f7db0a
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/antnsn/mal-sync:v1.0.52f06e72cef36
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
openssl@3.3.2-r1
3.3.7-r0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
openssl@3.3.1-r1
3.3.7-r0
1
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
openssl@3.5.5-r0
3.5.6-r0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.