StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,549
of 17,805 indexed, latest versions
Container images
2,914
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,549 of 17,805 indexed charts deploy, on 2,914 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,679
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0906
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5329
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm420
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,549 by stars
ChartLatestAffected imagesRadar Score
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,864
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,400
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

3,950
netbirdnetbird1.9.03 of 4See more

netbird netbird 1.9.0

3 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
netbirdio/relay:0.46.0d32f82514a24
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
netbirdio/signal:0.46.0e8f392611152
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,482
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

1,598
neuralbank-stackneuralbank-stack0.1.02 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
openssl@1:3.5.1-3.el9
1:3.5.5-3.el9_8

Open the chart page →

5,348
neurofaceneurofaceVerified publisher1.4.23 of 3See more

neuroface neuroface 1.4.2

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
openssl@1:3.5.5-2.el9_8
1:3.5.5-3.el9_8
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8

Open the chart page →

7,648
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

3,921
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

5,519
nfl-walletnfl-walletVerified publisher0.1.34 of 4See more

nfl-wallet nfl-wallet 0.1.3

4 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
openssl@1:1.1.1k-15.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

13,514
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,326
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,326
nginx-sitenginx-site0.1.01 of 1See more

nginx-site nginx-site 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
amaraiheanacho/nginx-site:latest5c86fccf5daa
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

989
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

23,264
booksonicnicholaswildeVerified publisher1.0.11 of 1See more

booksonic nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

17,055
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
nodejs@14.18.2-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.13
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

24,393
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
nodejs@14.18.2-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.13
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

25,570
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
nodejs@14.19.3-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.17
openssl1.0@1.0.2n-1ubuntu5.9
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

22,443
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
nodejs@14.19.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.14
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

23,647
ciliumnicklasfrahm-ciliumVerified publisher0.7.43 of 6See more

cilium nicklasfrahm-cilium 0.7.4

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
quay.io/cilium/hubble-ui:v0.13.3661d5de70501
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

7,265
wireguardnicklasfrahm-wireguard0.2.01 of 1See more

wireguard nicklasfrahm-wireguard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,161
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/redis:8.2.24521b581dbdd
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

2,515
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,841
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

7,071
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

3,426
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,973
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,350
node-hostnamenode-hostnameVerified publisher1.0.11 of 1See more

node-hostname node-hostname 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
christianhuth/node-hostname:1.0.1c07f414a3e4b
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,032
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,019
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,019
firehose-corenodeifyVerified publisher1.2.62 of 2See more

firehose-core nodeify 1.2.6

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

6,627
firehose-ethereumnodeifyVerified publisher1.7.12 of 2See more

firehose-ethereum nodeify 1.7.1

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

5,742
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

4,784
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

22,827
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,265
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,338
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,321
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm8
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,579
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
openssl@1.1.1-1ubuntu2.1~18.04.5
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

95,380
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

4,999
firecrawlobeoneVerified publisher3.0.71 of 5See more

firecrawl obeone 3.0.7

1 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

10,178
libretranslateobeoneVerified publisher1.0.71 of 1See more

libretranslate obeone 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
libretranslate/libretranslate:v1.9.61de2d7056bb8
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,055
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,116
lensoci-ai-incubations0.1.144 of 16See more

lens oci-ai-incubations 0.1.14

4 of the 16 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
openssl@3.5.0-r0
3.5.6-r0
grafana/grafana:12.1.1a1701c218024
openssl@3.5.1-r0
3.5.6-r0
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

17,265
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,357
cluster-managerocm-helm-chartsVerified publisher1.3.11 of 1See more

cluster-manager ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

822
klusterletocm-helm-chartsVerified publisher1.3.11 of 1See more

klusterlet ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

822
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8

Open the chart page →

1,619
multicluster-controlplaneocm-helm-chartsVerified publisher0.8.01 of 1See more

multicluster-controlplane ocm-helm-charts 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
openssl@1:1.1.1k-16.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

626
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,638

Container images carrying it

2,914 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
openssl@3.3.1-r3
3.3.7-r0
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
openssl@3.0.2-0ubuntu1.29
no fix listed
1
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
openssl@3.3.0-r2
3.3.7-r0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/madeddie/opds-aggregator:latest60c56021c552
openssl@3.3.6-r0
3.3.7-r0
1
ghcr.io/mailcow/prometheus-exporter:2.1.0cb76395b84eb
openssl@3.3.5-r0
3.3.7-r0
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
openssl@3.5.0-r0
3.5.6-r0
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
openssl@3.3.4-r0
3.3.7-r0
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
openssl@3.5.0-r0
3.5.6-r0
1
ghcr.io/marthydavid/kafka-keda-golang-consumer:0.0.4e07644865dd1
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/marthydavid/kafka-keda-golang-producer:0.0.454b242c7bf2b
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/matanbaruch/cursor-admin-api-exporter:0.1.8ba3a29fc479a
openssl@3.3.4-r0
3.3.7-r0
1
ghcr.io/mattn/picoclaw:latest517556c8b144
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
openssl@3.5.1-1
3.5.5-1~deb13u2
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
openssl@3.5.1-1
3.5.5-1~deb13u2
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
openssl@3.5.1-1
3.5.5-1~deb13u2
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.