StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,518
of 17,787 indexed, latest versions
Container images
2,896
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,518 of 17,787 indexed charts deploy, on 2,896 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,662
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0904
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5330
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,518 by stars
ChartLatestAffected imagesRadar Score
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
hmediade/printserver-init:latest7f005eb6c718
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

10,918
home-ha-mockhome-ha-mockVerified publisher2.0.51 of 1See more

home-ha-mock home-ha-mock 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,054
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

14,629
home-security-demohome-security-demoVerified publisher2.0.121 of 3See more

home-security-demo home-security-demo 2.0.12

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,137
hammerspace-csihscsi1.2.81 of 6See more

hammerspace-csi hscsi 1.2.8

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8

Open the chart page →

4,440
httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

8,732
eoloplanthttpd-eoloplant0.1.06 of 7See more

eoloplant httpd-eoloplant 0.1.0

6 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
codeurjc/server:v1.0310bea5b1ee7
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
codeurjc/weatherservice:v1.0b9e2f7234349
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

32,336
nexus3huangchengwu-helm-chart0.1.01 of 1See more

nexus3 huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sonatype/nexus3:3.53.04bd975493104
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

4,462
prometheushuangchengwu-helm-chart0.1.02 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
apache/skywalking-ui:9.2.0295f1dc87d98
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

16,482
skywalking-v1huangchengwu-helm-chart0.1.02 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3
apache/skywalking-ui:8.9.180530f0308a5
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

20,727
sing-boxhuscker-chartsVerified publisher1.0.71 of 1See more

sing-box huscker-charts 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,443
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-frontend:2.15.2dc6384d10cc8
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

3,355
jaegerhuseyinbabalVerified publisher0.1.01 of 3See more

jaeger huseyinbabal 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:latestab6f1a1f0fb4
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,478
kubetaghuseyinbabalVerified publisher1.0.21 of 2See more

kubetag huseyinbabal 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/huseyinbabal/kubetag:lateste161eddc59a0
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,277
hydrahydraVerified publisher0.9.51 of 2See more

hydra hydra 0.9.5

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,038
isolated-vmhydraVerified publisher0.9.41 of 1See more

isolated-vm hydra 0.9.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

7,749
hydrogen-webhydrogen-web0.1.101 of 1See more

hydrogen-web hydrogen-web 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/element-hq/hydrogen-web:v0.5.12d15d14b201a
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

725
hyperglance-helmhyperglance-helmVerified publisher10.0.54 of 6See more

hyperglance-helm hyperglance-helm 10.0.5

4 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
openssl@3.0.2-0ubuntu1.23
no fix listed
hyperglance/init:postgres9fd5faf1fe80
openssl@3.0.2-0ubuntu1.23
no fix listed
hyperglance/init:apacheb2f8c6d52623
openssl@3.0.2-0ubuntu1.23
no fix listed
hyperglance/postgresql-v2:10.0.5eb4d383894b8
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

11,171
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

7,184
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

7,902
iam-eks-user-mapperiam-eks-user-mapper1.6.01 of 1See more

iam-eks-user-mapper iam-eks-user-mapper 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

1,649
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,770
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
openssl@1.0.2g-1ubuntu4.10
no fix listed
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

57,728
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
openssl@1:1.1.1c-15.el8
1:1.1.1k-17.el8_6
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
openssl@1:1.1.1c-15.el8
1:1.1.1k-17.el8_6

Open the chart page →

12,460
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
openssl@1.1.0g-2ubuntu4.3
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

12,632
ibm-swift-sampleibm-charts1.1.21 of 1See more

ibm-swift-sample ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ibmcom/icp-swift-sample:latestb5d8c6714dbc
openssl@1.0.2g-1ubuntu4.12
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

25,184
ibm-ws-dyn-agent-devibm-charts1.0.01 of 1See more

ibm-ws-dyn-agent-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

19,309
ibm-ucv-prodibm-helm5.2.63 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

3 of the 16 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
bitnamilegacy/rabbitmq:4.1.2fac502149c40
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
openssl@1:1.1.1-8.el8
1:1.1.1k-17.el8_6

Open the chart page →

11,975
tolgeeicoretechVerified publisher0.46.11 of 3See more

tolgee icoretech 0.46.1

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

2,715
monitoring-stackict-platformVerified publisher0.4.04 of 13See more

monitoring-stack ict-platform 0.4.0

4 of the 13 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/memcached:1.6.39-alpinec8503d4491ed
openssl@3.5.4-r0
3.5.6-r0
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
openssl@3.5.4-r0
3.5.6-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

9,597
ingress-nginxifmethod-helm-charts4.12.11 of 2See more

ingress-nginx ifmethod-helm-charts 4.12.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,476
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

3,181
eoloserverihuertas2021-vmartinp2021-helm0.1.05 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

5 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
codeurjc/toposervice:v1.09fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
codeurjc/weatherservice:v1.0b9e2f7234349
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23

Open the chart page →

27,812
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

9,032
ikigaiikigai-chartVerified publisher0.0.95 of 58See more

ikigai ikigai-chart 0.0.9

5 of the 58 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
jupyterhub/k8s-hub:1.2.0e4770285aaf7
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
kuberay/operator:v1.0.04e6ac8a3a2c4
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
library/zookeeper:3.8-temurin55d1e5b2e601
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

37,844
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,586
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.1.0eb10d5bf045c
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

1,836
ilum-marquezilumVerified publisher6.7.03 of 3See more

ilum-marquez ilum 6.7.0

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
ilum/marquez:0.54.06e1d709d41f8
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
ilum/marquez-web:0.53.2716437a51a6c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

6,282
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,748
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,236
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,838
plausible-analyticsimioVerified publisher0.4.25 of 5See more

plausible-analytics imio 0.4.2

5 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
library/postgres:17.6-alpineef257d85f76e
openssl@3.5.4-r0
3.5.6-r0
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

10,152
smtp4devimioVerified publisher0.1.11 of 1See more

smtp4dev imio 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rnwood/smtp4dev:3.6.1912304153668
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,205
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23

Open the chart page →

3,350
kore-boardimprowisedVerified publisher0.5.81 of 4See more

kore-board improwised 0.5.8

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

16,226
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23

Open the chart page →

5,360
pgcatimprowisedVerified publisher0.1.01 of 1See more

pgcat improwised 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,316
proxysqlimprowisedVerified publisher1.0.01 of 1See more

proxysql improwised 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
improwised/proxysql:master-6b26e59-171765063828940522e8b7
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,183
infisical-agent-injectorinfisical-charts0.1.121 of 1See more

infisical-agent-injector infisical-charts 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

761
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
library/influxdb:1.12.3-datab0f9fc41ed79
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,736

Container images carrying it

2,896 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
mastercloudapps/weatherservice:v1.23de859d29c116
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
4
natsio/nats-server-config-reloader:0.23.064cb6c858e79
openssl@3.5.5-r0
3.5.6-r0
4
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
4
openquantumsafe/openssl3:latest543fb00ce31d
openssl@3.3.2-r4
3.3.7-r0
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
4
shashkist/flask-contacts-app:latest581de1fd6084
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
4
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
openssl@3.3.2-r0
3.3.7-r0
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
4
quay.io/strimzi/operator:0.37.052f376e64b9b
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
4
bitnamilegacy/kubectl:latestcd354d5b2556
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
3
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
3
ciscolabs/rtsp-client:latesta7b60ec88285
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
3
ciscolabs/rtsp-server:latestb59fc10bb821
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
3
cloudpirates/image-minio:RELEASE.2025-10-15T17-29-55Z-hardened8dc02a7e5093
openssl@3.3.6-r0
3.3.7-r0
3
cloudve/cloudlaunch-server:latest4a3d7fae90bb
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
3
cockroachdb/cockroach-self-signer-cert:1.1007a49acec18d
openssl@1:1.1.1k-15.el8_6
1:1.1.1k-17.el8_6
3
codeurjc/planner:v1.0800cf520c245
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
3
curlimages/curl:8.18.0d94d07ba9e7d
openssl@3.5.4-r0
3.5.6-r0
3
derailed/popeye:v0.22.18e68e22c7663
openssl@3.3.2-r4
3.3.7-r0
3
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
3
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
3
envoyproxy/envoy:v1.31.02bf7f042e396
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23
3
gchq/hdfs:3.3.35ec58edbb2db
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
3
grafana/grafana:11.3.0a0f881232a6f
openssl@3.3.2-r0
3.3.7-r0
3
guacamole/guacamole:1.6.0f344085e618b
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
3
jacobalberty/unifi:v10.0.162896c0ab82d33
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
3
jaegertracing/all-in-one:latestab6f1a1f0fb4
openssl@3.5.4-r0
3.5.6-r0
3
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
openssl@3.3.2-r0
3.3.7-r0
3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
openssl@3.3.3-r0
3.3.7-r0
3
kubegems/kubegems:v1.24.10a730bcf9322a
openssl@3.5.4-r0
3.5.6-r0
3
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.6-r0
3
library/nginx:1.25:1.25.5a484819eb602
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
3
library/postgres:15.7-alpine:15.7-alpine3.20468d34fefd63
openssl@3.3.1-r3
3.3.7-r0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
openssl@1:1.1.1g-12.el8_3
1:1.1.1k-17.el8_6
3
natsio/nats-box:0.19.28031d190c7ee
openssl@3.5.4-r0
3.5.6-r0
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
3
opencsghq/psql:latest57def8e77d0f
openssl@3.3.2-r4
3.3.7-r0
3
selenium/hub:3.141.5902f251d48d5f
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
3
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
3
xenondb/percona:5.7.330e26872a2b67
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
openssl@3.0.9-1
3.0.19-1~deb12u2
3
ghcr.io/dexidp/dex:v2.45.18499afd690c4
openssl@3.5.5-r0
3.5.6-r0
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
3
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
openssl@3.3.3-r0
3.3.7-r0
3
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.