StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,509
of 17,803 indexed, latest versions
Container images
2,886
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,509 of 17,803 indexed charts deploy, on 2,886 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,657
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0900
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5329
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,509 by stars
ChartLatestAffected imagesRadar Score
wraftwraft0.1.123 of 9See more

wraft wraft 0.1.12

3 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

10,311
redirectwyrihaximusnetVerified publisher1.1.01 of 1See more

redirect wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,594
aeneabotygdrassilOfficialVerified publisher0.2.01 of 2See more

aeneabot ygdrassil 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
elautoestopista/aeneabot:4.2.1125ba620d528
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,694
raponchiygdrassilOfficialVerified publisher0.4.01 of 1See more

raponchi ygdrassil 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
elautoestopista/raponchi:0.3.0b6f74db9fc81
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

1,314
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
nodejs@16.14.2-deb-1nodesource1
openssl@3.0.2-0ubuntu1.9
no fix listed
3.0.2-0ubuntu1.23

Open the chart page →

9,865
qleverzazukoVerified publisher0.7.11 of 2See more

qlever zazuko 0.7.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

2,513
velero-notificationszokeber-velero-notificationsVerified publisher0.1.101 of 2See more

velero-notifications zokeber-velero-notifications 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

728
backendzymtraceOfficialVerified publisher26.9.24 of 6See more

backend zymtrace 26.9.2

4 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.14.14b627d7a9bc0e
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.23
library/postgres:17.4304ab8135187
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.29a32b89c0c19
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

9,295
acos-prometheus-exporter-helm-charta10-prometheus-exporter0.1.01 of 1See more

acos-prometheus-exporter-helm-chart a10-prometheus-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
a10networks/acos-prometheus-exporter:latest8dc58d434d71
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

74,391
aaqaaqVerified publisher0.3.01 of 1See more

aaq aaq 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,016
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,600
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

7,719
active-mqactivemq-helm-chartVerified publisher1.8.21 of 3See more

active-mq activemq-helm-chart 1.8.2

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.44.00305c26f19ed
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

3,246
open5gsadaptivenetlabVerified publisher1.0.32 of 3See more

open5gs adaptivenetlab 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
free5gmano/nextepc-mongodb:latest36f806935519
openssl@1.0.2g-1ubuntu4.14
1.0.2g-1ubuntu4.20+esm15
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

99,481
linkstackadnoctemVerified publisher0.4.01 of 1See more

linkstack adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linkstackorg/linkstack:latest1c8b05399ee4
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,094
popeyeadnoctemVerified publisher0.3.01 of 1See more

popeye adnoctem 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,341
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
quay.io/aerokube/keygen:1.0.1578934444f04
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23

Open the chart page →

7,944
msockperfaetrius2.0.82 of 2See more

msockperf aetrius 2.0.8

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.9
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.9

Open the chart page →

4,277
kourierahhhhVerified publisher0.18.11 of 1See more

kourier ahhhh 0.18.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.34-latestcfc0678bc03c
openssl@3.0.2-0ubuntu1.23
no fix listed

Open the chart page →

1,823
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,994
airbyteairbyte-v2Verified publisher2.3.02 of 10See more

airbyte airbyte-v2 2.3.0

2 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
airbyte/db:2.3.000cc017f0393
openssl@3.5.4-r0
3.5.6-r0
temporalio/auto-setup:1.27.2b44cbfeb43db
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

12,100
aktoakto0.2.03 of 7See more

akto akto 0.2.0

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
keelhq/keel:latest73714afb4443
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

13,780
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v172035434f455
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

37,573
akto-hybrid-redactakto1.44.72 of 5See more

akto-hybrid-redact akto 1.44.7

2 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
openssl@3.3.2-r0
3.3.7-r0
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8

Open the chart page →

4,845
akto-k8s-ebpf-openshiftakto0.1.11 of 1See more

akto-k8s-ebpf-openshift akto 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,279
akto-mini-runtime-shaakto0.7.232 of 3See more

akto-mini-runtime-sha akto 0.7.23

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
public.ecr.aws/aktosecurity/redisdigest-pinned47200b041382
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

3,301
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

6,640
akto-mini-testing-kafkaakto1.42.13 of 5See more

akto-mini-testing-kafka akto 1.42.1

3 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
keelhq/keel:latest73714afb4443
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

6,426
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8

Open the chart page →

1,868
akto-protectionakto0.1.03 of 4See more

akto-protection akto 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
keelhq/keel:latest73714afb4443
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

11,315
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.072035434f455
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

35,613
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

4,878
akto-testing-db-layerakto1.42.172 of 2See more

akto-testing-db-layer akto 1.42.17

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
openssl@3.3.2-r0
3.3.7-r0
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

31,442
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

53,616
sambaalekcVerified publisher1.1.01 of 1See more

samba alekc 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,135
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,362
lidarralexmorbo-lidarrVerified publisher0.1.21 of 1See more

lidarr alexmorbo-lidarr 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,871
quialexmorbo-quiVerified publisher0.1.01 of 1See more

qui alexmorbo-qui 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/autobrr/qui:v1.14.110b7945d4f09
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,617
tubearchivistalexmorbo-tubearchivistVerified publisher0.1.01 of 2See more

tubearchivist alexmorbo-tubearchivist 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
valkey/valkey:9.0.1546304417fea
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

1,700
redisalexvanderberkelVerified publisher2.2.01 of 1See more

redis alexvanderberkel 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/redis:8.2.15fa2edb1e408
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,894
glancealpineworks0.1.11 of 1See more

glance alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.46df86a7e8868
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,150
versitygwalpineworks0.1.21 of 1See more

versitygw alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
versity/versitygw:v1.0.145192635d0353
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,259
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,261
amorphieamorphie0.1.24 of 18See more

amorphie amorphie 0.1.2

4 of the 18 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
openssl@3.3.0-r2
3.3.7-r0
camunda/zeebe:8.4.5ab5abc09e407
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
hazelcast/management-center:5.3.2f9d34300d330
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23

Open the chart page →

28,377
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

7,626
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,261
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

11,614
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,076
wmbusmetersandrenarchyVerified publisher1.2.01 of 1See more

wmbusmeters andrenarchy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
wmbusmeters/wmbusmeters:release-1.18.0d82715d9ae22
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

516
games-on-whalesangelnu2.0.04 of 7See more

games-on-whales angelnu 2.0.0

4 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

113,781

Container images carrying it

2,886 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
openssl@1:3.5.1-3.el9
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
openssl@1:3.5.5-2.el9_8
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
openssl@1:3.5.5-2.el9_8
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
openssl@1:1.1.1k-15.el8_6
1:1.1.1k-17.el8_6
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
openssl@1:1.1.1c-2.el8_1.1
1:1.1.1k-17.el8_6
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8
1
quay.io/minio/directpv:v4.0.84560083eb77d
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
openssl@1.0.2g-1ubuntu4.17
1.0.2g-1ubuntu4.20+esm15
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
openssl@1:1.1.1g-11.el8
1:1.1.1k-17.el8_6
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/open-cluster-management/multicluster-controlplane:latest9888240f644b
openssl@1:1.1.1k-16.el8_6
1:1.1.1k-17.el8_6
1
quay.io/openshift/origin-cli:4.66722d5041b47
openssl@1:1.1.1c-19.el8_2
1:1.1.1k-17.el8_6
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
openssl@1:1.1.1c-21.el8_2
1:1.1.1k-17.el8_6
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
openssl@1:1.1.1k-12.el8_6
1:1.1.1k-17.el8_6
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
openssl@3.5.4-r0
3.5.6-r0
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/opsmxpublic/ubi8-oes-ui:isd-spin-2025.10.01-e6f6f01-2025121006405d934bb66884
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/projectquay/clair:4.9.023329c3368e4
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.6-r0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssl@1:3.0.7-17.el9_2
1:3.5.5-3.el9_8
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.