CVE-2026-28390
HighAdvisory
Published 7 Apr 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.008
- 55th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,601
- of 17,832 indexed, latest versions
- Container images
- 2,970
- deployed by those charts
- Fix available
- 4 of 5
- affected packages
Red Hat Security Advisory: openssl security update
Carried by container images the latest versions of 2,601 of 17,832 indexed charts deploy, on 2,970 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more | 1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more | 1,710 |
| opensslapk | 3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more | 3.3.7-r0, 3.5.6-r0, 3.6.2-r0 | 927 |
| opensslrpm | 1:1.1.1-8.el8, 1:1.1.1c-2.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8+33 more | 1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 1:3.5.5-3.el10_2+1 more | 333 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 more | no fix listed | 22 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more | 1.0.2n-1ubuntu5.13+esm4 | 20 |
- OSV records
- ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:22314RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
- Also known as
- CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2
Charts affected
2,601 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.4 | 1 of 6See more | 8,128 |
Container images carrying it
2,970 by charts deploying them
A fixed version is listed for 4 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| matrixdotorg/ | c3c4a9de2a0b | openssl | 3.0.19-1~deb12u2 | 1 |
| matterlabs/ | 5dadc06bdf3b | openssl | 3.0.19-1~deb12u2 | 1 |
| matterlabs/ | 6cbfea4c694a | openssl | 3.0.19-1~deb12u2 | 1 |
| mauricenino/ | 236997816917 | openssl | 3.3.7-r0 | 1 |
| mavrick1/ | 45ca0429a1d4 | openssl | 3.3.7-r0 | 1 |
| mavrick1/ | 56bd8eaa53a4 | openssl | 3.3.7-r0 | 1 |
| mawad98/ | 99422c56a274 | openssl | 3.5.5-1~deb13u2 | 1 |
| mbround18/ | 70bd4da591cd | openssl | 3.0.2-0ubuntu1.23 | 1 |
| mccutchen/ | 24528cf5229d | openssl | 3.0.19-1~deb12u2 | 1 |
| mcronce/ | 09519cd7bd2f | openssl | 3.0.19-1~deb12u2 | 1 |
| mediagis/ | c15e941485ef | openssl | 1.1.1f-1ubuntu2.24+esm3 | 1 |
| mediagis/ | d0eae7b51374 | openssl | 3.0.2-0ubuntu1.23 | 1 |
| megaease/ | fad1c7452958 | openssl | 3.5.6-r0 | 1 |
| merlos/ | a38fc7e09ed7 | openssl | 3.0.19-1~deb12u2 | 1 |
| metabase/ | 7807bc5cad17 | openssl | 3.3.7-r0 | 1 |
| microslac/ | 5c1eb1f5c64d | openssl | 3.0.19-1~deb12u2 | 1 |
| microslac/ | 1b24afcd71ff | openssl | 3.0.19-1~deb12u2 | 1 |
| microslac/ | a90091a1f524 | openssl | 1:1.1.1k-17.el8_6 | 1 |
| microslac/ | 0f75997fcbe5 | openssl | 3.0.19-1~deb12u2 | 1 |
| microslac/ | 216ea6832a56 | openssl | 3.0.19-1~deb12u2 | 1 |
| middlewareeng/ | 747d880812f1 | openssl | 3.0.19-1~deb12u2 | 1 |
| mikefarah/ | 2c100efaca06 | openssl | 3.3.7-r0 | 1 |
| milvusdb/ | fededb2f2d63 | openssl | 3.0.2-0ubuntu1.23 | 1 |
| milvusdb/ | a3a55e1c1497 | openssl | 1.1.1f-1ubuntu2.24+esm3 | 1 |
| miniflux/ | a3ca6bbc1f74 | openssl | 3.5.6-r0 | 1 |
| minio/ | 2a374c124d44 | openssl | 1:1.1.1k-17.el8_6 | 1 |
| minio/ | 1484c87239ea | openssl | 1:1.1.1k-17.el8_6 | 1 |
| minio/ | bd11edda91f3 | openssl | 1:1.1.1k-17.el8_6 | 1 |
| minio/ | fc6bedc99355 | openssl | 1:1.1.1k-17.el8_6 | 1 |
| minio/ | 170b154d2c61 | openssl | 1:1.1.1k-17.el8_6 | 1 |
| minio/ | 2adc5be088f5 | openssl | 1:1.1.1k-17.el8_6 | 1 |
| mintproject/ | 83aade2c1855 | openssl | 1.1.1f-1ubuntu2.24+esm3 | 1 |
| mintproject/ | 02260d20a21f | openssl | 3.0.19-1~deb12u2 | 1 |
| miqm/ | c5c211717d9b | openssl | 3.0.19-1~deb12u2 | 1 |
| mlikiowa/ | 2cc70b45244a | openssl | 3.0.2-0ubuntu1.23 | 1 |
| moonrailgun/ | b528c8f8fcc4 | openssl | 3.3.7-r0 | 1 |
| moreillon/ | d7d4a5463525 | openssl | 3.0.19-1~deb12u2 | 1 |
| moreillon/ | e418cc694bd5 | openssl | 3.0.19-1~deb12u2 | 1 |
| moreillon/ | e8fd856e593d | openssl | 3.0.19-1~deb12u2 | 1 |
| moreillon/ | 3caa8f710ee0 | openssl | 3.0.19-1~deb12u2 | 1 |
| moreillon/ | 5f0a38498271 | openssl | 3.5.5-1~deb13u2 | 1 |
| moreillon/ | 6597e6b98d21 | openssl | 3.0.19-1~deb12u2 | 1 |
| moreillon/ | d2ee0423b797 | openssl | 3.0.19-1~deb12u2 | 1 |
| mpepping/ | 91e04eaaa1ba | openssl | 3.3.7-r0 | 1 |
| mrasif/ | 375a1ed8fdc0 | openssl | 3.5.6-r0 | 1 |
| mshanley80/ | 5b189a70c0fb | openssl | 1.1.1f-1ubuntu2.24+esm3 | 1 |
| muhammedgamal/ | 74b4cd69b6fa | openssl | 3.0.19-1~deb12u2 | 1 |
| muluder/ | 43b597a93da7 | nodejs openssl | no fix listed 1.0.2g-1ubuntu4.20+esm15 | 1 |
| murtazashah46/ | 4d11726cf803 | openssl | 3.0.19-1~deb12u2 | 1 |
| mvance/ | 4bf67b567f39 | openssl | 3.0.19-1~deb12u2 | 1 |