StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,565
of 17,813 indexed, latest versions
Container images
2,938
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,565 of 17,813 indexed charts deploy, on 2,938 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,692
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0916
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5330
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm420
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,565 by stars
ChartLatestAffected imagesRadar Score
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.9

Open the chart page →

2,166
atlas-operatorxxl-job-adminVerified publisher0.7.111 of 1See more

atlas-operator xxl-job-admin 0.7.11

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
arigaio/atlas-operator:0.7.111c4caa13c92b
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

1,197
cloudeye-exporterxxl-job-adminVerified publisher0.1.21 of 1See more

cloudeye-exporter xxl-job-admin 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,697
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,185
nightingalexxl-job-adminVerified publisher0.2.111 of 6See more

nightingale xxl-job-admin 0.2.11

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

9,738
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,196
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

9,526
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,718
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

2,485
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

6,026
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

3,700
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,573
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,191
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm8
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

9,296
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

7,966

Container images carrying it

2,938 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/middleware-labs/mw-lang-aggregator:0.1.0ae6e13970ec2
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/miniflux/miniflux:2.2.83a11ac10969e
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
openssl@3.5.1-1
3.5.5-1~deb13u2
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.61.2f04925fe1fa6
openssl@3.3.1-r0
3.3.7-r0
1
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
1
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/openfaas/gateway:0.27.1382b15393116e
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
openssl@3.5.0-r0
3.5.6-r0
1
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
openssl@3.5.5-r0
3.5.6-r0
1
ghcr.io/open-telemetry/demo:1.12.0-productcatalogservice008b9b662289
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/open-telemetry/demo:3.1.0-payment10d6bd20d8a0
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/open-telemetry/demo:1.12.0-checkoutservice380eccdc29e9
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/open-telemetry/demo:3.1.0-image-provider46d1a7e95109
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.