StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,549
of 17,805 indexed, latest versions
Container images
2,914
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,549 of 17,805 indexed charts deploy, on 2,914 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,679
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0906
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5329
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm420
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,549 by stars
ChartLatestAffected imagesRadar Score
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,864
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

2,400
core-keeper-dedicatednerkho-helm-charts0.1.11 of 1See more

core-keeper-dedicated nerkho-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
escaping/core-keeper-dedicated:latest87fa79255962
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

3,950
netbirdnetbird1.9.03 of 4See more

netbird netbird 1.9.0

3 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
netbirdio/relay:0.46.0d32f82514a24
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
netbirdio/signal:0.46.0e8f392611152
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,482
netris-dpu-agentnetrisai0.1.01 of 1See more

netris-dpu-agent netrisai 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
netrisai/bare-metal-dpu-agent:4.7.0.003c271efe749d0
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

1,598
neuralbank-stackneuralbank-stack0.1.02 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
openssl@1:3.5.1-3.el9
1:3.5.5-3.el9_8

Open the chart page →

5,348
neurofaceneurofaceVerified publisher1.4.23 of 3See more

neuroface neuroface 1.4.2

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
openssl@1:3.5.5-2.el9_8
1:3.5.5-3.el9_8
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8

Open the chart page →

7,648
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

3,921
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

5,519
nfl-walletnfl-walletVerified publisher0.1.34 of 4See more

nfl-wallet nfl-wallet 0.1.3

4 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
openssl@1:1.1.1k-15.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

13,514
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,326
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,326
nginx-sitenginx-site0.1.01 of 1See more

nginx-site nginx-site 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
amaraiheanacho/nginx-site:latest5c86fccf5daa
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

989
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

23,264
booksonicnicholaswildeVerified publisher1.0.11 of 1See more

booksonic nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic:version-1.2677efca1065d
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

17,055
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
nodejs@14.18.2-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.13
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

24,393
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
nodejs@14.18.2-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.13
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

25,570
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
nodejs@14.19.3-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.17
openssl1.0@1.0.2n-1ubuntu5.9
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

22,443
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
nodejs@14.19.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.14
openssl1.0@1.0.2n-1ubuntu5.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

23,647
ciliumnicklasfrahm-ciliumVerified publisher0.7.43 of 6See more

cilium nicklasfrahm-cilium 0.7.4

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
quay.io/cilium/hubble-ui:v0.13.3661d5de70501
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

7,265
wireguardnicklasfrahm-wireguard0.2.01 of 1See more

wireguard nicklasfrahm-wireguard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,161
terraform-backendnimbolus0.3.21 of 2See more

terraform-backend nimbolus 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/redis:8.2.24521b581dbdd
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

2,515
yopassnimbolus0.6.11 of 2See more

yopass nimbolus 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jhaals/yopass:11.17.026873480863b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,841
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

7,071
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

3,426
redisnineinfra-charts0.7.51 of 1See more

redis nineinfra-charts 0.7.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,973
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,350
node-hostnamenode-hostnameVerified publisher1.0.11 of 1See more

node-hostname node-hostname 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
christianhuth/node-hostname:1.0.1c07f414a3e4b
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,032
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,019
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

2,019
firehose-corenodeifyVerified publisher1.2.62 of 2See more

firehose-core nodeify 1.2.6

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

6,627
firehose-ethereumnodeifyVerified publisher1.7.12 of 2See more

firehose-ethereum nodeify 1.7.1

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

5,742
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

4,784
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

22,827
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,265
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,338
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,321
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm8
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

27,579
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
openssl@1.1.1-1ubuntu2.1~18.04.5
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

95,380
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

4,999
firecrawlobeoneVerified publisher3.0.71 of 5See more

firecrawl obeone 3.0.7

1 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/rabbitmq:3.13-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

10,178
libretranslateobeoneVerified publisher1.0.71 of 1See more

libretranslate obeone 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
libretranslate/libretranslate:v1.9.61de2d7056bb8
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

2,055
olvid-botobeoneVerified publisher0.3.31 of 1See more

olvid-bot obeone 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
olvid/bot-daemon:2.0.1e0e6b165d879
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9

Open the chart page →

2,116
lensoci-ai-incubations0.1.144 of 16See more

lens oci-ai-incubations 0.1.14

4 of the 16 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
openssl@3.5.0-r0
3.5.6-r0
grafana/grafana:12.1.1a1701c218024
openssl@3.5.1-r0
3.5.6-r0
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

17,265
ocisocis-community0.1.01 of 1See more

ocis ocis-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
owncloud/ocis:8.0.1b38fd8fdd58f
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,357
cluster-managerocm-helm-chartsVerified publisher1.3.11 of 1See more

cluster-manager ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

822
klusterletocm-helm-chartsVerified publisher1.3.11 of 1See more

klusterlet ocm-helm-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

822
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8

Open the chart page →

1,619
multicluster-controlplaneocm-helm-chartsVerified publisher0.8.01 of 1See more

multicluster-controlplane ocm-helm-charts 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
openssl@1:1.1.1k-16.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

626
octantisoctantis0.1.01 of 1See more

octantis octantis 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/vinny1892/octantis:latest45459c0910fc
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,638

Container images carrying it

2,914 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
openssl@3.5.0-r0
3.5.6-r0
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
openssl@3.1.4-r2
3.3.7-r0
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
openssl@3.3.1-r0
3.3.7-r0
1
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
ghcr.io/szpadel/languagetool-server:6.568fdab22b2a9
openssl@3.3.2-r0
3.3.7-r0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/tale/headplane:0.6.39476cc5adb12
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
openssl@3.5.1-r0
3.5.6-r0
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/themesama/kubernetes-kustomize-patcher:latestb1bf0669e3a0
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/topolvm/pie:0.18.0aa467443e407
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
openssl@3.0.2-0ubuntu1.26
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
openssl@3.3.3-r0
3.3.7-r0
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
openssl@3.5.4-r0
3.5.6-r0
1
ghcr.io/usememos/memos:0.24.04723d86e6797
openssl@3.3.2-r4
3.3.7-r0
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
openssl@3.3.6-r0
3.3.7-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
openssl@3.3.2-r0
3.3.7-r0
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.