StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,306
of 17,787 indexed, latest versions
Container images
2,569
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,306 of 17,787 indexed charts deploy, on 2,569 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,662
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0904
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,306 by stars
ChartLatestAffected imagesRadar Score
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,553
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,233
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

12,034
homerlmatfyVerified publisher0.1.11 of 1See more

homer lmatfy 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
b4bz/homer:v25.02.2c367265313f9
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

345
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,392
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

2,155
tempo-distributedloafoe1.20.12 of 2See more

tempo-distributed loafoe 1.20.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
openssl@3.3.1-r3
3.3.7-r0
library/memcached:1.6.29-alpine462ae4a35c26
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

2,020
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

947
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

7,516
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,507
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

9,021
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23

Open the chart page →

6,674
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,970
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

23,255
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

5,910
loxilbloxilbVerified publisher0.1.02 of 2See more

loxilb loxilb 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
openssl@3.0.2-0ubuntu1.26
no fix listed
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

4,502
lsdisklsdiskVerified publisher2.0.71 of 4See more

lsdisk lsdisk 2.0.7

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

5,032
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

17,836
elastictranscoderluiscajl0.46.04 of 4See more

elastictranscoder luiscajl 0.46.0

4 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
elastictranscoder/media:627e21dc963ab3858c6b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
elastictranscoder/media-storage:f6d861a026208b8c2359
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
elastictranscoder/transcoder:627e21dcb4a0327029e6
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

58,225
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:a90e0e5d5966cbc14d5d
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,002
hyperglassm0nsterrr-hyperglassVerified publisher4.2.12 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

4,659
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,786
magistralamagistrala-devopsVerified publisher0.16.25 of 42See more

magistrala magistrala-devops 0.16.2

5 of the 42 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31-latestcaa5b411be16
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
library/nats:2.10.17-alpineb7752304692b
openssl@3.3.1-r0
3.3.7-r0
natsio/nats-server-config-reloader:0.15.05b21830a9e9d
openssl@3.3.0-r2
3.3.7-r0
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

24,488
docker-mailservermailserverVerified publisher0.2.657 of 9See more

docker-mailserver mailserver 0.2.65

7 of the 9 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
jeboehm/mailserver-filter:5.0.92e756949e537d
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-mda:5.0.92d03fb7bae0a2
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-mta:5.0.925fb2f31c940d
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-virus:5.0.92eb5c1c260d11
openssl@3.3.4-r0
3.3.7-r0
jeboehm/mailserver-web:5.0.929da13edf5aa8
openssl@3.5.2-r0
3.5.6-r0
mvance/unbound:1.22.076906da36d18
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

10,908
mangadev-hello-worldmangadev0.3.01 of 1See more

mangadev-hello-world mangadev 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
wagnermanganelli164/webserver-hello-world:0.3.0d4ef27a4f180
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

863
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

6,722
eirmargaysVerified publisher1.7.21 of 1See more

eir margays 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
margays/eir:v1.7.22883fdd06fd7
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

801
marge-botmarge-bot-helm1.3.51 of 1See more

marge-bot marge-bot-helm 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,541
consumermarthydavidVerified publisher0.1.61 of 1See more

consumer marthydavid 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

805
producermarthydavidVerified publisher0.1.61 of 1See more

producer marthydavid 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

805
circleci-runnermatic-insurance0.1.11 of 1See more

circleci-runner matic-insurance 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
circleci/runner:launch-agent9bdc62f02162
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

4,150
kruisematrixone-operatorVerified publisher1.8.31 of 2See more

kruise matrixone-operator 1.8.3

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
openkruise/kruise-manager:v1.8.30482722b4e56
openssl@3.3.6-r0
3.3.7-r0

Open the chart page →

1,767
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,095
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

8,351
mayastormayastorVerified publisher2.12.12 of 31See more

mayastor mayastor 2.12.1

2 of the 31 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

21,178
eoloplantmca-eoloplaner0.1.03 of 7See more

eoloplant mca-eoloplaner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

29,712
backstagemcwarmanVerified publisher0.10.102 of 2See more

backstage mcwarman 0.10.10

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

9,707
mdai-hubmdai-hubVerified publisher0.10.11 of 14See more

mdai-hub mdai-hub 0.10.1

1 of the 14 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

4,746
applicationmediamarktsaturn1.37.01 of 1See more

application mediamarktsaturn 1.37.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quay.io/heubeck/examiner:1.14.61154472ff8c4
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

801
tinymediamanagermedia-servarrVerified publisher1.6.21 of 2See more

tinymediamanager media-servarr 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

7,760
cameramedia-streaming-meshVerified publisher0.2.52 of 3See more

camera media-streaming-mesh 0.2.5

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

18,712
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

3,707
msmmedia-streaming-meshVerified publisher0.1.175 of 6See more

msm media-streaming-mesh 0.1.17

5 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9

Open the chart page →

11,478
msm-rtspmedia-streaming-meshVerified publisher0.0.22 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

18,712
rtspmedia-streaming-meshVerified publisher0.0.142 of 2See more

rtsp media-streaming-mesh 0.0.14

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

18,712
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,849
memgptmemgptVerified publisher0.3.191 of 2See more

memgpt memgpt 0.3.19

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ankane/pgvector:v0.5.1d3a9d8ac27bb
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,872
istiomesosphere1.25.11 of 2See more

istio mesosphere 1.25.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,786
istio-helm-cnimesosphere1.25.11 of 1See more

istio-helm-cni mesosphere 1.25.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/install-cni:1.29.0ce27c9ce43c8
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,572
istio-helm-istiodmesosphere1.25.12 of 2See more

istio-helm-istiod mesosphere 1.25.1

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
istio/pilot:1.29.0325156535773
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
mesosphere/kubectl:v1.35.0-alpineea01a9387771
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

3,817

Container images carrying it

2,569 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
hazelcast/hazelcast:5.5.05dd5d31c7a06
openssl@3.3.1-r3
3.3.7-r0
2
helmforge/kubectl:1.35.3c3f97e954c47
openssl@3.5.5-r0
3.5.6-r0
2
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
openssl@3.0.9-1
3.0.19-1~deb12u2
2
hookiesolutions/webhookie:latest0629694246ba
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
2
ilum/marquez:0.54.06e1d709d41f8
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
2
ilum/ui:6.7.3998937726679
openssl@3.5.5-r0
3.5.6-r0
2
interlayhq/interbtc:latesta66d0e35e70f
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
2
interlayhq/interbtc-clients:vault-masterc3e311de67da
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3
2
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
2
istio/examples-bookinfo-reviews-v1:1.14.0ee156b8aefd6
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
2
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
2
istio/examples-bookinfo-reviews-v2:1.14.0eab80bcd2132
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
2
istio/examples-bookinfo-reviews-v3:1.14.01e37fca43550
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
2
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
2
istio/kubectl:1.5.10dbb7726d1bf0
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
2
istio/proxyv2:1.18.0757d28c24100
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
2
istio/proxyv2:1.10.3a78b7a165744
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
2
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
openssl@3.3.6-r0
3.3.7-r0
2
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
openssl@3.5.1-r0
3.5.6-r0
2
kurento/kurento-media-server:latest03c0d34d0828
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
2
langgenius/dify-sandbox:0.2.009b7e8705673
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
library/cassandra:3.11.65aa8400b4b3b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
2
library/cassandra:4.1.37cbcec0086ac
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.23
2
library/elasticsearch:7.17.35e6ac15bf6a5
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
2
library/elasticsearch:8.19.1289729a95066a
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
2
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
2
library/mariadb:10.10334b315c10e5
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.23
2
library/mariadb:12.0.2:12.0-noble607835cd628b
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
2
library/mariadb:10.692e50059ea0a
openssl@3.0.2-0ubuntu1.26
no fix listed
2
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
2
library/mongo:7.0-jammy:7-jammy406a4fdca9fc
openssl@3.0.2-0ubuntu1.26
no fix listed
2
library/mongo:5.041108d183e97
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
2
library/mongo:4.2.358b25d51baa1
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
2
library/mongo:7b096b4cb9269
openssl@3.0.2-0ubuntu1.29
no fix listed
2
library/mongo:7.0b6421fd6d1c5
openssl@3.0.2-0ubuntu1.26
no fix listed
2
library/nginx:1.27.098f8ec75657d
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
2
library/nginx:1.29.49dd288848f44
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
2
library/phpmyadmin:5.2.16e75aa8f767c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
library/postgres:16.109f23e02d766
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
library/postgres:18.11090bc3a8ccf
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
2
library/postgres:16.24aea012537ed
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
library/postgres:18.06f3e42ad37de
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
2
library/postgres:16.4e62fbf9d3e2b
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
library/postgres:13-alpinefb9065b6e3e2
openssl@3.5.4-r0
3.5.6-r0
2
library/python:3.7eedf63967cdb
openssl@3.0.9-1
3.0.19-1~deb12u2
2
library/rabbitmq:3.13.6-management-alpine611107e29cce
openssl@3.3.1-r3
3.3.7-r0
2
library/rabbitmq:4.1.0-management935b3f84c1e4
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.