StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,574
of 17,821 indexed, latest versions
Container images
2,947
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,574 of 17,821 indexed charts deploy, on 2,947 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,697
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0919
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8+32 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5331
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm421
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,574 by stars
ChartLatestAffected imagesRadar Score
dev-feedrm3lVerified publisher3.1.22 of 3See more

dev-feed rm3l 3.1.2

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
rm3l/dev-feed-api:latestf03921cd3b26
openssl@1:3.0.7-17.el9_2
1:3.5.5-3.el9_8

Open the chart page →

9,890
mac-ouirm3lVerified publisher1.25.01 of 1See more

mac-oui rm3l 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rm3l/mac-oui:1.8.03a5e1f95c132
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6

Open the chart page →

1,977
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

10,175
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,148
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

7,796
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,957
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,645
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,608
routehub-client-hubroutehub-helm1.0.02 of 3See more

routehub-client-hub routehub-helm 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm3
timescale/timescaledb-ha:pg164f288c0a5213
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

12,918
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

2,988
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

3,940
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

5,323
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

13,604
kyoorubxkubeVerified publisher0.1.106 of 9See more

kyoo rubxkube 0.1.10

6 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
getmeili/meilisearch:v1.11.0b9be3d2d4251
openssl@3.3.2-r0
3.3.7-r0
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
openssl@3.3.2-r4
3.3.7-r0
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

30,550
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23

Open the chart page →

11,095
devpisb-helm-charts0.3.01 of 1See more

devpi sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

959
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

38,725
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

2,208
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

5,240
sentry-k8ssentry-k8sVerified publisher1.4.14 of 11See more

sentry-k8s sentry-k8s 1.4.1

4 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
confluentinc/cp-kafka:7.6.683dbca3efd2a
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
library/redis:6.2.20-alpine77697a75da9f
openssl@3.3.5-r0
3.3.7-r0
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

17,006
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

3,427
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
dserio83/velero-watchdog:0.1.8d5deae589229
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,518
scaffoldsigstoreVerified publisher0.6.1152 of 15See more

scaffold sigstore 0.6.115

2 of the 15 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
curlimages/curldigest-pinned:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.6-r0
library/redisdigest-pinned148bb5411c18
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

7,855
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,926
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
openssl@3.0.2-0ubuntu1.23
no fix listed

Open the chart page →

2,036
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,565
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
altinity/metrics-exporter:0.20.01a46d104406d
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

6,424
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,915
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

251,257
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
valkey/valkey:8.1.61f84517eca8e
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,946
artifact-hubsoftonic1.19.04 of 8See more

artifact-hub softonic 1.19.0

4 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
artifacthub/db-migrator:v1.19.02a746b289fcd
openssl@3.3.1-r0
3.3.7-r0
artifacthub/hub:v1.19.0111918d8c399
openssl@3.3.1-r0
3.3.7-r0
artifacthub/postgres:latest4fd34fa635cc
openssl@3.5.1-1
3.5.5-1~deb13u2
artifacthub/scanner:v1.19.0323d026e78c3
openssl@3.3.1-r0
3.3.7-r0

Open the chart page →

14,542
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

7,365
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,689
speckle-serverspeckleVerified publisher2.26.34 of 4See more

speckle-server speckle 2.26.3

4 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.26.3d51e1b0cf231
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
speckle/speckle-preview-service:2.26.3092384dba45d
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
speckle/speckle-server:2.26.379f14a2bf931
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
speckle/speckle-webhook-service:2.26.3c58eb372c488
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,239
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,487
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23

Open the chart page →

2,671
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

11,467
gethstakewise2.5.81 of 3See more

geth stakewise 2.5.8

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ethereum/client-go:v1.15.101f36ca5922a5
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,289
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,660
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

13,622
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

102,725
stornxstornxVerified publisher1.1.14 of 9See more

stornx stornx 1.1.1

4 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
alazidis/stornx:1.1.1602d4f7f090c
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
istio/pilot:1.29.1f8b0e412ac4a
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
quay.io/kiali/kiali:v2.23.07652b1285f50
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8

Open the chart page →

11,773
supabasesupabse0.8.02 of 11See more

supabase supabse 0.8.0

2 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
kong/kong:3.9.16addf50e6bd8
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

17,986
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

2,162
headscaleszpadel-chartsVerified publisher0.30.21 of 3See more

headscale szpadel-charts 0.30.2

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.6.39476cc5adb12
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

1,748
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,069
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,069
tocktock0.6.37 of 9See more

tock tock 0.6.3

7 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
tock/bot_admin:25.10.7df3e38c77a38
openssl@3.5.5-r0
3.5.6-r0
tock/bot_api:25.10.7dd5d5c70e333
openssl@3.5.5-r0
3.5.6-r0
tock/build_worker:25.10.7080cb6b08d5b
openssl@3.5.5-r0
3.5.6-r0
tock/duckling:25.10.7ac1f3f1a1e9c
openssl@3.5.5-r0
3.5.6-r0
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
tock/kotlin_compiler:25.10.7c9c0fb40089a
openssl@3.5.5-r0
3.5.6-r0
tock/nlp_api:25.10.7c04ffe67b977
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

13,745
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

4,105
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23

Open the chart page →

1,931

Container images carrying it

2,947 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/projectquay/clair:4.9.023329c3368e4
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/projectquay/clair:4.7.28d38ffa8fad7
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.6-r0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssl@1:3.0.7-17.el9_2
1:3.5.5-3.el9_8
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/reiml/smtp-gotify:latest80ffa9d2044a
openssl@3.3.6-r0
3.3.7-r0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
openssl@1:1.1.1k-4.el8
1:1.1.1k-17.el8_6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
openssl@3.3.1-r3
3.3.7-r0
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.6-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssl@3.0.9-1
3.0.19-1~deb12u2
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.24+esm3
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.6-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.6-r0
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.5-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
openssl@3.3.2-r0
3.3.7-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.6-r0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.