StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.024
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,622
of 17,844 indexed, latest versions
Container images
2,996
deployed by those charts
Fix available
5 of 6
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,622 of 17,844 indexed charts deploy, on 2,996 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,731
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0932
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8+33 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 1:3.5.5-3.el10_2+1 more331
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm421
openssl-1_1rpm1.1.1l-150500.17.22.11.1.1l-150500.17.54.12
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:22314RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0fSUSE-SU-2026:1550-1
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,622 by stars
ChartLatestAffected imagesRadar Score
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

6,537
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

21,614
batch-job-helmbatch-job0.1.11 of 2See more

batch-job-helm batch-job 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
thomaszy2077/batch:1a271ab8a80bd
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,937
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

4,361
qbittorrent-vpnbdclark-helm-chartsVerified publisher0.7.61 of 2See more

qbittorrent-vpn bdclark-helm-charts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.41.11a5bf4b4820a
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,033
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,214
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
behnambm/docker-sample:v1bd3ad88afff9
openssl@3.3.1-r0
3.3.7-r0

Open the chart page →

2,834
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,585
keycloakbhuwanupadhyayVerified publisher1.0.01 of 2See more

keycloak bhuwanupadhyay 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.25227edcc7595
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

6,601
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

7,750
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

5,571
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

75,448
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
nodejs@14.17.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.9
openssl1.0@1.0.2n-1ubuntu5.6
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

87,643
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,403
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,627
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

13,721
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,570
istio-bookinfobookinfo1.2.23 of 6See more

istio-bookinfo bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

19,753
colosseumbook-k8sinfra-v21.0.184 of 5See more

colosseum book-k8sinfra-v2 1.0.18

4 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
openssl@3.0.2-0ubuntu1.25
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
sysnet4admin/colosseum-prm:log5802bfcd7fed
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
sysnet4admin/colosseum-rwd:log74ded2d92f07
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

28,888
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,507
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,874
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
library/cassandra:3.11.65aa8400b4b3b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

19,801
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

8,492
kube-prometheus-stackbook-k8sinfra-v265.5.12 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
openssl@3.3.2-r0
3.3.7-r0
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

6,147
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

1,908
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.61 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,703
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,162
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,585
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,585
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,585
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
openssl@1.1.0g-2ubuntu4.3
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

10,955
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,937
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

76,596
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,138
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,347
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,813
pages-microservicebusi-adsVerified publisher1.0.02 of 3See more

pages-microservice busi-ads 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,585
bpabusiness-partner-agentVerified publisher0.12.41 of 3See more

bpa business-partner-agent 0.12.4

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bcgovimages/aries-cloudagent:py36-1.16-1_0.7.4faa2e2d21916
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

11,873
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

3,142
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

2,482
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

10,881
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,585
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

8,360
geoservercamptocamp20.0.37 of 12See more

geoserver camptocamp2 0.0.3

7 of the 12 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

90,148
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,515
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,278
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
puppet/puppet-agent:7.14.00b6fd9a6b7da
openssl@1.1.1-1ubuntu2.1~18.04.15
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

6,375
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

6,178
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,458
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latest68b19aee1c64
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

14,690

Container images carrying it

2,996 by charts deploying them

A fixed version is listed for 5 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/projectquay/clair:4.9.023329c3368e4
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/projectquay/clair:4.7.28d38ffa8fad7
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.6-r0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssl@1:3.0.7-17.el9_2
1:3.5.5-3.el9_8
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/reiml/smtp-gotify:latest80ffa9d2044a
openssl@3.3.6-r0
3.3.7-r0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
openssl@1:1.1.1k-4.el8
1:1.1.1k-17.el8_6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
openssl@3.3.1-r3
3.3.7-r0
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.6-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssl@3.0.9-1
3.0.19-1~deb12u2
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.24+esm3
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.6-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.6-r0
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.5-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
openssl@3.3.2-r0
3.3.7-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.6-r0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.