StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,565
of 17,813 indexed, latest versions
Container images
2,938
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,565 of 17,813 indexed charts deploy, on 2,938 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,692
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0916
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5330
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm420
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,565 by stars
ChartLatestAffected imagesRadar Score
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

4,567
direktivdirektivVerified publisher0.10.02 of 6See more

direktiv direktiv 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
openssl@3.3.3-r0
3.3.7-r0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

3,791
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,429
bearhugmugsdjjudas21Verified publisher0.1.01 of 1See more

bearhugmugs djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/bearhugmugs:0.1.14fa898a52d97
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

705
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

7,367
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,007
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

875
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,413
ownclouddjjudas21Verified publisher0.3.233 of 3See more

owncloud djjudas21 0.3.23

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
owncloud/server:10.16.3b3f9efdcd7f7
openssl@3.0.2-0ubuntu1.25
no fix listed
valkey/valkey:8.1.481db6d39e1bb
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

10,292
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9

Open the chart page →

92,708
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,055
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

5,389
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

14,860
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,872
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,872
dnation-kubernetes-monitoring-stackdnationcloud4.0.36 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.3

6 of the 17 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
openssl@3.3.2-r0
3.3.7-r0
library/memcached:1.6.32-alpine0a27d9d5084f
openssl@3.3.2-r1
3.3.7-r0
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
openssl@3.3.3-r0
3.3.7-r0
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

23,543
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
openssl@1.1.1-1ubuntu2.1~18.04.4
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

9,013
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,106
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,515
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

2,869
dominodomino-iisasVerified publisher0.3.13 of 3See more

domino domino-iisas 0.3.1

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
ghcr.io/iisas/domino-frontend:k8s8e53861be292
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/iisas/domino-rest:latest3009350bfc11
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

10,511
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8

Open the chart page →

3,202
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

25,063
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,209
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,274
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,898
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.03 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

24,825
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
quay.io/keycloak/keycloak:20.0054ef67eb7da
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

56,289
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.23
ghcr.io/ctron/kubectl:1.25e37d61b5277c
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

30,832
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

6,924
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,494
cloudflaredduck-helm1.1.31 of 1See more

cloudflared duck-helm 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

1,481
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

3,523
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-28390.

Open the chart page →

4,267
duplicacyduplicacy0.1.22 of 2See more

duplicacy duplicacy 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
openssl@3.5.5-r0
3.5.6-r0
drumsergio/duplicacy-exporter:0.3.4ca3476077215
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,424
kubernetes-database-scalerdvdlevanonVerified publisher0.1.21 of 1See more

kubernetes-database-scaler dvdlevanon 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,024
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

19,999
dyff-frontenddyff-frontendVerified publisher0.20.21 of 1See more

dyff-frontend dyff-frontend 0.20.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,123
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

9,455
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

2,000
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,518
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,690
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

13,756
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,881
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

11,487
openfaas2eclipse-aeriosVerified publisher12.0.52 of 6See more

openfaas2 eclipse-aerios 12.0.5

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
openssl@3.3.2-r4
3.3.7-r0
ghcr.io/openfaas/gateway:0.27.1382b15393116e
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

6,844
orion-ldeclipse-aeriosVerified publisher1.0.02 of 2See more

orion-ld eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
fiware/orion-ld:1.10.03c490a746f65
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
library/mongo:7.0.12ae1cf99fa7bf
openssl@3.0.2-0ubuntu1.17
3.0.2-0ubuntu1.23

Open the chart page →

9,829
self-awarenesseclipse-aeriosVerified publisher1.4.41 of 2See more

self-awareness eclipse-aerios 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,275
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

1,969
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,873

Container images carrying it

2,938 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.29a32b89c0c19
openssl@3.5.0-r0
3.5.6-r0
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
mcr.microsoft.com/mssql/server:2022-latest4402d880dd4c
openssl@3.0.2-0ubuntu1.29
no fix listed
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
openssl@3.3.5-1.azl3
3.3.5-5
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
openssl@3.3.5-3.azl3
3.3.5-5
1
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
openssl@3.3.5-3.azl3
3.3.5-5
1
mcr.microsoft.com/playwright/mcp:v0.0.43e101b832b34d
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
openssl@3.3.2-r0
3.3.7-r0
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
openssl@3.5.5-r0
3.5.6-r0
1
public.ecr.aws/aktosecurity/redis47200b041382
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
openssl@3.5.1-r0
3.5.6-r0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
public.ecr.aws/dynatrace/dynatrace-operator:v1.3.0f68901a54664
openssl@1:3.0.7-28.el9_4
1:3.5.5-3.el9_8
1
public.ecr.aws/g4a0y2u8/unifie-store:staging-19925a2057fabc948
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
openssl@3.5.4-1~deb13u2+e1
3.5.5-1~deb13u2
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
openssl@3.5.4-1~deb13u2+e1
3.5.5-1~deb13u2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
openssl@3.3.5-r0
3.3.7-r0
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
public.ecr.aws/lumigo/lumigo-kubernetes-operator:69491c39346b19
openssl@3.5.1-r0
3.5.6-r0
1
public.ecr.aws/lumigo/lumigo-kubernetes-telemetry-proxy:691d548e59c2c8
openssl@3.5.1-r0
3.5.6-r0
1
public.ecr.aws/lumigo/lumigo-kubernetes-watchdog:696458fcd61e0c
openssl@3.5.1-r0
3.5.6-r0
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/optimizely/webhook-broker:v0.2.3cfc92cc2de65
openssl@3.3.4-r0
3.3.7-r0
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm8
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
public.ecr.aws/truefoundrycloud/timberio/vector:v0.50.05833723de9e4
openssl@3.5.4-r0
3.5.6-r0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
public.ecr.aws/zinclabs/openobserve:v0.8.127f8de509169
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.