StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,507
of 17,792 indexed, latest versions
Container images
2,876
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,507 of 17,792 indexed charts deploy, on 2,876 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,650
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0897
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5329
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,507 by stars
ChartLatestAffected imagesRadar Score
omec-control-planeopencord0.1.314 of 8See more

omec-control-plane opencord 0.1.31

4 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm15
omecproject/c3po-hssdb:master-latest28a90cc26716
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3
omecproject/mme-exporter:paging-latestbcc5f19fd676
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
omecproject/openmme:master-latest64776cb9edb3
openssl@1.0.2g-1ubuntu4.17
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

40,825
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

12,942
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

38,902
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

12,626
sebaopencord1.0.05 of 17See more

seba opencord 1.0.0

5 of the 17 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
openssl@1.0.2g-1ubuntu4.9
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-cli:1.6.0c4e41e92f046
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-netconf:1.6.037f80524c207
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-ofagent:1.6.09ee8c1f4428c
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
voltha/voltha-voltha:1.6.0ff596b62de59
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

93,946
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
voltha/voltha-onos:5.1.8e038acb950d3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

41,101
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,051
opencost-lensopencost-lens1.0.01 of 2See more

opencost-lens opencost-lens 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,110
everest-db-namespaceopeneverestVerified publisher1.16.21 of 1See more

everest-db-namespace openeverest 1.16.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
percona/everest-helmtools:0.0.1904458d04a18
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

769
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

741
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,162
kafka-connectoropenfaas0.7.151 of 1See more

kafka-connector openfaas 0.7.15

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,164
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,071
pro-builderopenfaas0.6.131 of 2See more

pro-builder openfaas 0.6.13

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,745
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

777
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

767
kruise-gameopenkruise1.1.01 of 1See more

kruise-game openkruise 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
openkruise/kruise-game-manager:v1.1.0d3c6d69d2c39
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

918
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,737
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,068
openlit-operatoropenlit0.2.21 of 1See more

openlit-operator openlit 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

858
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

7,471
openobserveopenobserve0.92.21 of 6See more

openobserve openobserve 0.92.2

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
natsio/nats-server-config-reloader:0.23.064cb6c858e79
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,166
openpanelopenpanel0.9.02 of 6See more

openpanel openpanel 0.9.0

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
library/redis:7.2.5-alpine6aaf3f5e6bc8
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

3,465
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

12,185
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8

Open the chart page →

2,386
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
andrianrf/backoffice-be:latest6036614803d4
openssl@1:3.0.7-6.el9_2
1:3.5.5-3.el9_8
andrianrf/iso-server:latest7da47f525c7d
openssl@1:3.0.7-6.el9_2
1:3.5.5-3.el9_8

Open the chart page →

35,116
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8

Open the chart page →

19,051
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8

Open the chart page →

13,041
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

7,866
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

16,563
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
openssl@1:3.5.1-5.el9_7
1:3.5.5-3.el9_8

Open the chart page →

4,170
kite-agentopenshift1.0.01 of 1See more

kite-agent openshift 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/fengyuanxing/zte_endogenous_security/kite-agent:V2.0.0734808044936
openssl@1:1.1.1k-15.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

5,863
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,113
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

19,471
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssl@1:3.0.7-17.el9_2
1:3.5.5-3.el9_8

Open the chart page →

8,643
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

13,612
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

11,740
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

13,573
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

13,556
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

13,460
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

13,105
voyager-gatewayopenshift2026.1.151 of 2See more

voyager-gateway openshift 2026.1.15

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,645
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8

Open the chart page →

2,063
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

15,602
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

36,252
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,005
kubernetes-syncopslevelVerified publisher0.8.01 of 1See more

kubernetes-sync opslevel 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,739

Container images carrying it

2,876 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ffutop/ddc-ph-kafka-egress:latest319d94c8481a
openssl@3.5.4-r0
3.5.6-r0
1
ffutop/ddc-ph-kafka-ingress:latest15832d4f19be
openssl@3.5.4-r0
3.5.6-r0
1
ffutop/ddc-transport-udp-receive:latest651ca530d787
openssl@3.5.4-r0
3.5.6-r0
1
ffutop/ddc-transport-udp-send:latest4222eb5ee847
openssl@3.5.4-r0
3.5.6-r0
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
openssl@3.5.4-r0
3.5.6-r0
1
firefart/requesttracker:5.0.40d6249906d8c
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
fiware/mintaka:0.7.092a3c5cf43c0
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
1
fiware/mintaka:latestefc6793388cc
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
1
fiware/orion-ld:1.10.03c490a746f65
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
flanksource/apm-hub:v0.0.471dacc3195bf9
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
flanksource/batch-runner:v1.0.44689687a7cf95
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
flashbots/mev-boost:1.8.07c486b5789da
openssl@3.3.1-r3
3.3.7-r0
1
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
fleetdm/fleet:v4.66.012e644b7f40e
openssl@3.3.3-r0
3.3.7-r0
1
flowable/flowable-rest:7.1.0b7ae287502cd
openssl@3.3.2-r0
3.3.7-r0
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
fluent/fluent-bit:4.0-debuge76397ef3983
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
flyway/flyway:9.1545b5d7cdc75a
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3
1
fnzv/dump1090:latestb3079b95c336
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
foldingathome/fah-gpu:latest5ef7742d1eb4
openssl@1.1.1-1ubuntu2.1~18.04.13
1.1.1-1ubuntu2.1~18.04.23+esm8
1
folioci/mod-agreements:latest29c3f233a498
openssl@3.3.1-r3
3.3.7-r0
1
folioci/mod-authtoken:latest995a25a33133
openssl@3.5.5-r0
3.5.6-r0
1
folioci/mod-courses:latest68ca414f5596
openssl@3.5.5-r0
3.5.6-r0
1
folioci/mod-ldp:latestb55696fd9065
openssl@3.3.3-r0
3.3.7-r0
1
folioci/mod-licenses:latestcfd6109bf477
openssl@3.3.1-r3
3.3.7-r0
1
folioci/mod-oa:latestae3b069d4ba5
openssl@3.3.1-r3
3.3.7-r0
1
folioci/mod-search:latest44d7ee9acdf6
openssl@3.5.1-r0
3.5.6-r0
1
folioci/mod-serials-management:latest571fa1ffe8c9
openssl@3.3.1-r3
3.3.7-r0
1
folioci/mod-service-interaction:latestf53c327a48e8
openssl@3.3.1-r3
3.3.7-r0
1
fosrl/newt:1.10.4ccd2b0e9a049
openssl@3.5.5-r0
3.5.6-r0
1
fosrl/pangolin:1.13.0c32ad797ab96
openssl@3.5.4-r0
3.5.6-r0
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
1
foxcpp/maddy:0.9.2a4b839985b9b
openssl@3.3.6-r0
3.3.7-r0
1
foxcpp/maddy:0.8.2eeb5813fc4d1
openssl@3.3.5-r0
3.3.7-r0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
1
free5gmano/nextepc-mongodb:latest36f806935519
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
1
freedom98/flask:k3.0d7ce1533f297
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
galaxy/cloudman-server:lateste5c265fe9fcd
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
galexrt/extended-ceph-exporter:v1.8.05373078a3a08
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
gchq/accumulo:2.0.1c460bb587d6d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.6-r0
1
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.6-r0
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8
1
geonode/geoserver:2.28.4-latest81b1d431b7e9
openssl@3.0.2-0ubuntu1.23
no fix listed
1
geopython/pycsw:3.0.0-beta284662ea6b78b
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.