StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,515
of 17,790 indexed, latest versions
Container images
2,895
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,515 of 17,790 indexed charts deploy, on 2,895 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,663
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0902
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5330
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,515 by stars
ChartLatestAffected imagesRadar Score
intel-gpu-exporterdefault-ghVerified publisher0.1.01 of 1See more

intel-gpu-exporter default-gh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,849
isponsorblocktvdefault-ghVerified publisher1.0.51 of 1See more

isponsorblocktv default-gh 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
openssl@3.3.5-r0
3.3.7-r0

Open the chart page →

547
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

6,092
dell-fan-controllerdell-fan-controllerVerified publisher1.0.71 of 1See more

dell-fan-controller dell-fan-controller 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

2,566
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
openssl@1:3.0.7-28.el9_4
1:3.5.5-3.el9_8

Open the chart page →

3,233
prometheus-dellhw-exporterdellhw-exporterVerified publisher1.3.01 of 1See more

prometheus-dellhw-exporter dellhw-exporter 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

1,855
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
openssl@1.1.1f-1ubuntu2.18
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,254
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

8,149
deployhubdeployhubVerified publisher10.0.4156 of 11See more

deployhub deployhub 10.0.415

6 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
openssl@3.5.4-r0
3.5.6-r0
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
openssl@3.5.4-r0
3.5.6-r0
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
openssl@3.6.0-r6
3.6.2-r0
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.2-r0
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.2-r0
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.2-r0

Open the chart page →

11,191
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

14,920
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,530
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

2,097
apachedevops0.1.02 of 4See more

apache devops 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.23

Open the chart page →

30,156
laraveldevops0.10.32 of 4See more

laravel devops 0.10.3

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.23

Open the chart page →

29,157
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

13,039
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,549
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,685
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

13,011
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

4,690
devtron-enterprisedevtron48.0.08 of 28See more

devtron-enterprise devtron 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm15
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

68,695
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,972
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,959
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,908
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,685
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

13,011
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

4,690
calicodevtron-labs0.1.11 of 4See more

calico devtron-labs 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6

Open the chart page →

10,094
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.08 of 28See more

devtron-enterprise devtron-labs 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
quay.io/devtron/git-sensor:94237c18-950-3941803c7bf249aa1
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm15
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/lens:3b3d6d0e-333-39292e886b8d2b54b
openssl@3.3.2-r4
3.3.7-r0
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

68,695
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

4,972
devtron-operatordevtron-labs0.23.32 of 11See more

devtron-operator devtron-labs 0.23.3

2 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

33,180
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,959
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,908
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,620
rateldgraph25.0.31 of 1See more

ratel dgraph 25.0.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dgraph/ratel:v25.0.34cae1ff95027
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,003
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,064
difydify1.0.03 of 4See more

dify dify 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
langgenius/dify-sandbox:0.2.009b7e8705673
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
langgenius/dify-web:1.0.0d64914ff0d6d
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

19,399
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,242
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

4,552
direktivdirektivVerified publisher0.10.02 of 6See more

direktiv direktiv 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
openssl@3.3.3-r0
3.3.7-r0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

3,480
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,395
bearhugmugsdjjudas21Verified publisher0.1.01 of 1See more

bearhugmugs djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/bearhugmugs:0.1.14fa898a52d97
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

704
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

7,203
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,006
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

873
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,412
ownclouddjjudas21Verified publisher0.3.233 of 3See more

owncloud djjudas21 0.3.23

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
owncloud/server:10.16.3b3f9efdcd7f7
openssl@3.0.2-0ubuntu1.25
no fix listed
valkey/valkey:8.1.481db6d39e1bb
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

10,144
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9

Open the chart page →

17,053
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,054
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

5,197

Container images carrying it

2,895 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:12.2.074144189b384
openssl@3.5.1-r0
3.5.6-r0
1
grafana/grafana:11.5.28b37a2f028f1
openssl@3.3.2-r1
3.3.7-r0
1
grafana/grafana:12.1.1a1701c218024
openssl@3.5.1-r0
3.5.6-r0
1
grafana/grafana:10.4.19a9043254ba16
openssl@3.3.3-r0
3.3.7-r0
1
grafana/grafana:12.0.2b5b59bfc7561
openssl@3.3.3-r0
3.3.7-r0
1
grafana/grafana:12.3.2ba93c9d192e5
openssl@3.5.4-r0
3.5.6-r0
1
grafana/grafana:11.3.1fa801ab6e1ae
openssl@3.3.2-r0
3.3.7-r0
1
grafana/loki:2.9.1035b02acc6765
openssl@3.3.1-r3
3.3.7-r0
1
grafana/oncall:v1.16.5499851658393
openssl@3.3.4-r0
3.3.7-r0
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
grafana/promtail:3.5.165bfae480b57
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
grafana/promtail:3.6.18dcfdf466da0
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
grafana/tempo:2.6.0f55a8a1937ff
openssl@3.3.1-r3
3.3.7-r0
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
graylog/graylog:6.1.1019de1aff48c2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
gresearch/armada-executor:latest393aff4aa8f2
openssl@3.3.3-r0
3.3.7-r0
1
gresearch/armada-lookout:latestf5e3226f1d33
openssl@3.3.3-r0
3.3.7-r0
1
gresearch/armada-lookout-ingester:latest3df14cda1855
openssl@3.3.3-r0
3.3.7-r0
1
gresearch/armada-scheduler:latest6141a6213fcb
openssl@3.3.3-r0
3.3.7-r0
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
openssl@3.5.4-r0
3.5.6-r0
1
gridgain/community:8.9.11d32d182a0e6a
openssl@3.3.2-r0
3.3.7-r0
1
gridgain/gridgain9:9.1.1895018390077b
openssl@3.5.5-r0
3.5.6-r0
1
grpl/grapple-cli:0.2.127c00aafee6629
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
1
guacamole/guacamole:1.5.50f62f6d17ab3
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
gulacedia/web-dvwa-new:v367b467d961ca
openssl@3.0.9-1
3.0.19-1~deb12u2
1
gurolakman/oam:4.0.0ed8fd2062548
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
gurolakman/ussigw-core:1.0.48739565c3ea2
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
hamidyousefi93/saam-test:latestc34f071f6ed0
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
openssl@3.3.2-r0
3.3.7-r0
1
hamzaarshad10/querypodpy:1.7154f38e8668e
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
hansehe/locust:1.1.0bc8e45262bc4
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hashicorp/boundary:0.21.037bf86488b74
openssl@3.3.5-r0
3.3.7-r0
1
hashicorp/terraform:1.9.7b77efab1a448
openssl@3.3.2-r0
3.3.7-r0
1
hashicorp/vault:1.19.0bbb7f98dc67d
openssl@3.3.3-r0
3.3.7-r0
1
hashicorp/vault-k8s:1.6.2103a2d817a74
openssl@3.3.3-r0
3.3.7-r0
1
hashicorp/vault-k8s:1.7.2ae3d307658b7
openssl@3.5.4-r0
3.5.6-r0
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hassroutyyoussef/orderservice:latest2fc3d1617928
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hassroutyyoussef/userservice:lateste0392e2b4a90
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
hasura/graphql-engine:v2.48.10f6c1c4b957d2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
haugene/transmission-openvpn:4.0059216cfae4b
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.