StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,615
of 17,837 indexed, latest versions
Container images
2,995
deployed by those charts
Fix available
5 of 6
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,615 of 17,837 indexed charts deploy, on 2,995 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,726
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0936
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8+33 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 1:3.5.5-3.el10_2+1 more331
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm421
openssl-1_1rpm1.1.1l-150500.17.22.11.1.1l-150500.17.54.12
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:22314RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0fSUSE-SU-2026:1550-1
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,615 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.02 of 2See more

helm-test test-helm-artifacthub 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
carlosmz87/test_helm_frontend:latest79f4b528f42a
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

11,927
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,498
chatqnatest-opea1.0.09 of 11See more

chatqna test-opea 1.0.0

9 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/chatqna:1.038c51b791efa
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/chatqna-conversation-ui:1.002d5674ca863
openssl@3.3.2-r0
3.3.7-r0
opea/embedding-tei:1.05c9639de61c1
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/reranking-tei:1.0e48613afb191
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/retriever-redis:1.0eb746b263705
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
redis/redis-stack:7.2.0-v91c5f43fddcdd
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

40,096
chatqna-uitest-opea0.9.01 of 1See more

chatqna-ui test-opea 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:v0.9bdb9ec215872
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

922
codegentest-opea1.0.04 of 5See more

codegen test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/codegen:1.058f91683892d
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/codegen-ui:1.02bee4eb66f3e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

29,474
codetranstest-opea1.0.04 of 5See more

codetrans test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/codetrans:1.0e2436483b73d
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/codetrans-ui:1.03ef121f34610
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

29,058
docsumtest-opea1.0.04 of 5See more

docsum test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/docsum:1.03eaa91849512
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
opea/docsum-ui:1.07f854e9bffaf
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
opea/llm-docsum-tgi:1.002f9e8fa5d71
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

29,538
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,318
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,353
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,852
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.23

Open the chart page →

5,768
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,117
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,330
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

9,789
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,349
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,349
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,489
uitest-opea1.0.01 of 1See more

ui test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/chatqna-conversation-ui:1.002d5674ca863
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

755
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,499
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
library/mongo:5.0.217c81758cb295
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

20,613
codeth-chartsVerified publisher0.1.01 of 1See more

code th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
collabora/code:24.04.13.2.101dc4ab83977
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,325
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,081
kasa-exporterth-chartsVerified publisher0.1.01 of 1See more

kasa-exporter th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
thelande/kasa_exporter:v0.2.3a1fdb8baa152
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

1,537
local-path-provisionerth-chartsVerified publisher0.0.291 of 1See more

local-path-provisioner th-charts 0.0.29

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

1,301
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,359
openmeteo-exporterth-chartsVerified publisher0.1.61 of 1See more

openmeteo-exporter th-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
thelande/openmeteo_exporter:v1.0.77e9072ace15f
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,382
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

10,200
prusa-exporterth-chartsVerified publisher0.3.01 of 1See more

prusa-exporter th-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
pubeldev/prusa_exporter:2.0.01091665a020a
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

909
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mongo:7-jammy84c4a18b60a0
openssl@3.0.2-0ubuntu1.29
no fix listed
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

6,026
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
openssl@1.0.2g-1ubuntu4.8
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

11,088
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

25,583
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,381
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,381
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,824
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,724
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

6,938
todolist-charttodolist-chart0.1.73 of 10See more

todolist-chart todolist-chart 0.1.7

3 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
openssl@3.5.1-1
3.5.5-1~deb13u2
erenozcan17/go_backend:v4.250b4f23422b6
openssl@3.5.1-r0
3.5.6-r0
erenozcan17/react_frontend:v4.56e1b14973f9b
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

6,964
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

3,211
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,116
token-servertoken-server1.0.91 of 1See more

token-server token-server 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
udhos/token-server:1.0.9728013f2fac1
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

1,249
netbirdtotmicro1.8.23 of 4See more

netbird totmicro 1.8.2

3 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
netbirdio/management:0.60.252682e5f48f9
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
netbirdio/relay:0.60.2a10762533793
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
netbirdio/signal:0.60.267176bcbf6ab
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

6,127
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6

Open the chart page →

12,759
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,229
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,672
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

3,094
trident-protect-bxp-previewtrident-protect100.2511.0-bxp-preview1 of 3See more

trident-protect-bxp-preview trident-protect 100.2511.0-bxp-preview

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v1.0.058b9fac358bd
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

2,202
saleor-appstrieb-work0.6.04 of 5See more

saleor-apps trieb-work 0.6.0

4 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
openssl@3.3.3-r0
3.3.7-r0
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

7,499
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
openssl@3.3.5-r0
3.3.7-r0

Open the chart page →

1,230
trivy-webhook-elasticsearchtrivy-webhook-elasticsearch0.1.41 of 1See more

trivy-webhook-elasticsearch trivy-webhook-elasticsearch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/lbi22/trivy-webhook-elasticsearch:v0.1.4b51b824e4f19
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

756
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

17,604

Container images carrying it

2,995 by charts deploying them

A fixed version is listed for 5 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.2-r0
1
quay.io/projectquay/clair:4.9.023329c3368e4
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/projectquay/clair:4.7.28d38ffa8fad7
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.6-r0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
openssl@1:3.0.7-17.el9_2
1:3.5.5-3.el9_8
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
openssl@1:3.0.7-27.el9
1:3.5.5-3.el9_8
1
quay.io/reiml/smtp-gotify:latest80ffa9d2044a
openssl@3.3.6-r0
3.3.7-r0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
openssl@1:1.1.1k-4.el8
1:1.1.1k-17.el8_6
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
openssl@3.3.1-r3
3.3.7-r0
1
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8
1
quay.io/strimzi/operator:0.45.158c727cd2e68
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.7-r0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.6-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssl@3.0.9-1
3.0.19-1~deb12u2
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm8
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.24+esm3
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.6-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.6-r0
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.5-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.6-r0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
openssl@3.3.2-r0
3.3.7-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.6-r0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
1

syft 1.42.1 · advisories as of 24 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.