StackRadar

CVE-2026-28389

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,306
of 17,787 indexed, latest versions
Container images
2,569
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-28389 affecting package openssl for versions less than 3.3.5-5

Carried by container images the latest versions of 2,306 of 17,787 indexed charts deploy, on 2,569 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,662
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0904
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl33.3.5-53
OSV records
ALPINE-CVE-2026-28389CGA-2r23-9xvx-4prrCGA-c3mq-2w7x-m4x8DEBIAN-CVE-2026-28389UBUNTU-CVE-2026-28389AZL-82067ECHO-ba3d-b3f7-03e8
Also known as
CGA-p78p-49m2-xjvw, CGA-rff8-35jv-r39r, USN-8155-1, USN-8155-2

Charts affected

2,306 by stars
ChartLatestAffected imagesRadar Score
openfaas2eclipse-aeriosVerified publisher12.0.52 of 6See more

openfaas2 eclipse-aerios 12.0.5

2 of the 6 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
openssl@3.3.2-r4
3.3.7-r0
ghcr.io/openfaas/gateway:0.27.1382b15393116e
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

6,678
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:7.0.12ae1cf99fa7bf
openssl@3.0.2-0ubuntu1.17
3.0.2-0ubuntu1.23

Open the chart page →

9,805
self-awarenesseclipse-aeriosVerified publisher1.4.41 of 2See more

self-awareness eclipse-aerios 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,195
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

1,907
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,850
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
openssl@1.1.1-1ubuntu2.1~18.04.13
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

10,995
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,233
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,344
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,150
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,284
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

1,663
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,333
eggybyte-chaineggybyte-hcr1.0.01 of 1See more

eggybyte-chain eggybyte-hcr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

806
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

3,944
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

8,046
seafileeleksbai0.1.12 of 3See more

seafile eleksbai 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
openssl@3.0.2-0ubuntu1.26
no fix listed
seafileltd/seafile-mc:9.0.106693911bcc40
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

25,239
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,960
redisemberstackVerified publisher1.0.211 of 1See more

redis emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/redis:8.0.2b43d2dcbbdb1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

1,902
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

10,605
kube-ecp-stackemqx-operator2.5.15 of 16See more

kube-ecp-stack emqx-operator 2.5.1

5 of the 16 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
datalayers/datalayers:v2.2.1017b292079239
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
openssl@3.3.2-r0
3.3.7-r0
emqx/ecp-ui:2.5.1e33e9816f147
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
emqxecp/otelcol:2.5.04c31d9bec846
openssl@3.3.2-r0
3.3.7-r0
library/telegraf:1.27507a3eecf809
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

22,845
enclaveenclave0.1.11 of 1See more

enclave enclave 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
enclavenetworks/enclave:latest0a99759300d1
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

2,740
kube-packetloss-exporterenixVerified publisher0.2.11 of 2See more

kube-packetloss-exporter enix 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,154
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/haproxy:2.9.6fc5748ff7c72
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,946
network-exporterenixVerified publisher0.3.01 of 1See more

network-exporter enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
syepes/network_exporter:1.8.000af1691570e
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,372
topomatikenixVerified publisher1.3.11 of 1See more

topomatik enix 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
openssl@3.0.2-0ubuntu1.23
no fix listed

Open the chart page →

2,152
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,150
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

7,265
eolicplantseolicplantsVerified publisher0.1.03 of 7See more

eolicplants eolicplants 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,349
eoloPlanteolo-plannerVerified publisher0.1.04 of 7See more

eoloPlant eolo-planner 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,667
eoloplannereoloplannerVerified publisher0.1.04 of 7See more

eoloplanner eoloplanner 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

32,336
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.04 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,667
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.03 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,314
eoloplannereoloplanner-molynx-gat0.1.03 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

28,539
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

27,188
eoloplanteoloplant1.0.04 of 7See more

eoloplant eoloplant 1.0.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23

Open the chart page →

27,667
eoloplantseoloplants-urjcVerified publisher0.1.03 of 7See more

eoloplants eoloplants-urjc 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

27,812
servereoloserverVerified publisher0.1.04 of 7See more

server eoloserver 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

32,336
flywayeosc-lot-1Verified publisher0.7.02 of 3See more

flyway eosc-lot-1 0.7.0

2 of the 3 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
alpine/git:v2.49.1c0280cf95723
openssl@3.5.4-r0
3.5.6-r0
flyway/flyway:9.1545b5d7cdc75a
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

9,383
mariadbeosc-lot-1Verified publisher0.2.01 of 2See more

mariadb eosc-lot-1 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,455
mariadb-backupeosc-lot-1Verified publisher0.5.01 of 2See more

mariadb-backup eosc-lot-1 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,455
mariadb-run-scripteosc-lot-1Verified publisher0.3.01 of 1See more

mariadb-run-script eosc-lot-1 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,455
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,316
postgresql-backupeosc-lot-1Verified publisher0.4.21 of 2See more

postgresql-backup eosc-lot-1 0.4.2

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine3.20468d34fefd63
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

1,467
rabbitmqeosc-lot-1Verified publisher0.3.01 of 2See more

rabbitmq eosc-lot-1 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

2,505
rediseosc-lot-1Verified publisher0.2.01 of 1See more

redis eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
redis/redis-stack-server:6.2.6-v251a58f32d412
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

3,100
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,897
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
library/mariadb:12.2.2b1cb255a9939
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

6,475
benchmarkoor-apiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-api ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
openssl@3.3.6-r0
3.3.7-r0

Open the chart page →

899
benchmarkoor-uiethereum-helm-chartsVerified publisher0.1.01 of 1See more

benchmarkoor-ui ethereum-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,339
blutgangethereum-helm-chartsVerified publisher0.0.121 of 1See more

blutgang ethereum-helm-charts 0.0.12

1 of the 1 container images this version deploys carry CVE-2026-28389.

Container imageDigestPackageFixed in
makemake1337/blutgang:latest8a55174fc830
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,524

Container images carrying it

2,569 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
library/rabbitmq:3.12.1-managementf020c06da226
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
2
library/redis148bb5411c18
openssl@3.3.3-r0
3.3.7-r0
2
library/redis:7.2.3a7cee7c8178f
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
library/redis:8.2.2f0957bcaa75f
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
2
library/wordpress:6.8.3-apache:6.8-apache30bff39330d1
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
2
library/zookeeper:3.9.5f258365d4882
openssl@3.0.2-0ubuntu1.26
no fix listed
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
openssl@3.3.2-r0
3.3.7-r0
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
2
linuxserver/ubooquity:2.1.2-ls369932d6759112
openssl@3.3.1-r3
3.3.7-r0
2
locustio/locust:2.32.2a0d4b88e42c1
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
2
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
2
mbentley/omada-controller:4.3f4e682274bed
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
openssl@1.1.1f-1ubuntu2
1.1.1f-1ubuntu2.24+esm3
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
openssl@3.5.4-r0
3.5.6-r0
2
mojaloop/reporting:v12.1.0d480a62103d6
openssl@3.3.3-r0
3.3.7-r0
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
openssl@3.3.3-r0
3.3.7-r0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
openssl@3.5.1-r0
3.5.6-r0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
openssl@3.3.3-r0
3.3.7-r0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
openssl@3.5.4-r0
3.5.6-r0
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
natsio/nats-server-config-reloader:0.21.110ff229eaf52
openssl@3.5.4-r0
3.5.6-r0
2
natsio/prometheus-nats-exporter:0.17.326c826662ac8
openssl@3.3.3-r0
3.3.7-r0
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
openssl@1.1.0g-2ubuntu4.1
1.1.1-1ubuntu2.1~18.04.23+esm8
2
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
openssl@3.3.3-r0
3.3.7-r0
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
2
opea/chatqna-conversation-ui:1.002d5674ca863
openssl@3.3.2-r0
3.3.7-r0
2
opea/embedding-tei:1.05c9639de61c1
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
2
opea/reranking-tei:1.0e48613afb191
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
2
opea/retriever-redis:1.0eb746b263705
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
2
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
openssl@3.3.3-r0
3.3.7-r0
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
opendatacube/ows:latest668cbb41473c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
2
openebs/node-disk-operator:2.1.06afe2123c457
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
2
oryd/kratos:v1.3.1fe2428f103a6
openssl@3.3.2-r1
3.3.7-r0
2
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.7-r0
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
quickwit/quickwit:v0.8.2363ff56ce456
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
rajnandan1/kener:3.2.1930407afca731
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2
2
rancher/local-path-provisioner:v0.0.3534ff0847cc47
openssl@3.5.5-r0
3.5.6-r0
2
rancher/local-path-provisioner:v0.0.299bebefa0b908
openssl@3.3.1-r3
3.3.7-r0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.