StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,501
of 17,787 indexed, latest versions
Container images
2,874
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,501 of 17,787 indexed charts deploy, on 2,874 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,651
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0894
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5329
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,501 by stars
ChartLatestAffected imagesRadar Score
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

2,312
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,145
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

13,459
bnkrbnkr1.0.51 of 2See more

bnkr bnkr 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
engrmth/bnkr:2.1.06d8464e6f0e8
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,253
istio-bookinfobookinfo1.2.23 of 6See more

istio-bookinfo bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

18,980
colosseumbook-k8sinfra-v21.0.184 of 5See more

colosseum book-k8sinfra-v2 1.0.18

4 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
openssl@3.0.2-0ubuntu1.25
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
sysnet4admin/colosseum-prm:log5802bfcd7fed
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
sysnet4admin/colosseum-rwd:log74ded2d92f07
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

26,996
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

6,220
grafanabook-k8sinfra-v28.8.21 of 1See more

grafana book-k8sinfra-v2 8.8.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,800
jaegerbook-k8sinfra-v23.4.02 of 5See more

jaeger book-k8sinfra-v2 3.4.0

2 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
library/cassandra:3.11.65aa8400b4b3b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

19,229
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

8,323
kube-prometheus-stackbook-k8sinfra-v265.5.12 of 6See more

kube-prometheus-stack book-k8sinfra-v2 65.5.1

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/grafana:11.2.2-security-01464eac539793
openssl@3.3.2-r0
3.3.7-r0
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

6,036
tempobook-k8sinfra-v21.10.31 of 1See more

tempo book-k8sinfra-v2 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/tempo:2.5.0f0200a9bff6d
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

1,859
bitmagnetbrandan-schmitz-helm-chartsVerified publisher1.0.61 of 2See more

bitmagnet brandan-schmitz-helm-charts 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,720
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,071
pagesbrian-pages1.0.02 of 3See more

pages brian-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,190
pagesbrixton-mayuribhavsar23-pages1.0.02 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,190
pagesbrixton-pages1.0.02 of 3See more

pages brixton-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,190
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
openssl@1.1.0g-2ubuntu4.3
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

10,776
plexbryanalves0.5.01 of 1See more

plex bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,707
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,306
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,869
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9

Open the chart page →

2,897
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
openssl@3.5.2-r0
3.5.6-r0

Open the chart page →

2,398
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

10,629
pagescamden-pages1.0.02 of 3See more

pages camden-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,190
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

8,001
geoservercamptocamp20.0.37 of 12See more

geoserver camptocamp2 0.0.3

7 of the 12 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

88,335
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

3,311
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

5,039
prometheus-puppetdb-sdcamptocamp38.0.21 of 2See more

prometheus-puppetdb-sd camptocamp3 8.0.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
puppet/puppet-agent:7.14.00b6fd9a6b7da
openssl@1.1.1-1ubuntu2.1~18.04.15
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

6,143
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23

Open the chart page →

5,886
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

10,776
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

14,130
pagescarina-pages1.0.02 of 3See more

pages carina-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,190
pagescarmel-pages-dell1.0.02 of 3See more

pages carmel-pages-dell 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,190
cassandra-clustercassandra-clusterVerified publisher0.1.01 of 1See more

cassandra-cluster cassandra-cluster 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/cassandra:3.11.10b095ff3248c6
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

9,473
temporalcastaiVerified publisher0.54.22 of 14See more

temporal castai 0.54.2

2 of the 14 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
openssl@3.3.2-r0
3.3.7-r0
temporalio/server:1.26.21e2626efcbc1
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

16,198
catalyst-agentscatalyst-agents0.1.302 of 18See more

catalyst-agents catalyst-agents 0.1.30

2 of the 18 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
alpine/k8s:1.32.3eec354133193
openssl@3.3.3-r0
3.3.7-r0
grafana/tempo:2.5.0f0200a9bff6d
openssl@3.3.0-r2
3.3.7-r0

Open the chart page →

15,027
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
openssl@1:1.1.1g-11.el8
1:1.1.1k-17.el8_6

Open the chart page →

6,389
cert-manager-alidns-webhookcert-manager-alidns-webhook0.1.41 of 1See more

cert-manager-alidns-webhook cert-manager-alidns-webhook 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/crazygit/cert-manager-alidns-webhook:0.1.4976be6506eb6
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,320
cert-manager-desec-webhookcert-manager-desec-webhook1.0.11 of 1See more

cert-manager-desec-webhook cert-manager-desec-webhook 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/luzifer/cert-manager-desec-webhook:v1.0.1fa1f6b2e9a6e
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,263
cert-manager-webhook-abioncert-manager-webhook-abion1.3.21 of 1See more

cert-manager-webhook-abion cert-manager-webhook-abion 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
abiondevelopment/cert-manager-webhook-abion:latestc741988fbd23
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

1,087
cert-manager-webhook-pdnscert-manager-webhook-pdns3.2.51 of 1See more

cert-manager-webhook-pdns cert-manager-webhook-pdns 3.2.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
zachomedia/cert-manager-webhook-pdns:v2.5.54940e227a39b
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,072
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
openssl@1:1.1.1k-4.el8
1:1.1.1k-17.el8_6

Open the chart page →

7,776
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,338
getoutlinecfi20171.2.02 of 4See more

getoutline cfi2017 1.2.0

2 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
library/redis:8.2.3d31852005202
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

4,412
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

15,371
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

1,338

Container images carrying it

2,874 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
openssl@3.5.1-r0
3.5.6-r0
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
openssl@3.5.0-r0
3.5.6-r0
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
2
ghcr.io/kiwigrid/k8s-sidecar:1.29.142002d66ddb3
openssl@3.3.2-r4
3.3.7-r0
2
ghcr.io/kluster-manager/cluster-auth:v0.5.1fba6fb872281
openssl@3.5.5-r0
3.5.6-r0
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm8
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.6-r0
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.23
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
openssl@3.0.18-1~deb12u2
3.0.19-1~deb12u2
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.6-r0
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm3
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
openssl@1:3.5.1-4.el9_7
1:3.5.5-3.el9_8
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.5-1~deb13u2
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
2
quay.io/curl/curl:8.16.0b17b13321678
openssl@3.5.2-r0
3.5.6-r0
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
2
quay.io/frrouting/frr:10.4.38745af1f9bbb
openssl@3.5.5-r0
3.5.6-r0
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6
2
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.6-r0
2
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
openssl@3.3.0-r2
3.3.7-r0
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
2
quay.io/mongodb/mongodb-kubernetes-operator:0.13.02dcc6393e6f7
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
2
quay.io/open-cluster-management/registration-operator:v1.3.1df6c926a2b54
openssl@1:3.5.1-7.el9_7
1:3.5.5-3.el9_8
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
openssl@1:1.1.1g-18.el8_4
1:1.1.1k-17.el8_6
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
openssl@1:1.1.1g-18.el8_4
1:1.1.1k-17.el8_6
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
openssl@1:3.2.2-6.el9_5.1
1:3.5.5-3.el9_8
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
openssl@3.5.4-r0
3.5.6-r0
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
openssl@3.5.5-r0
3.5.6-r0
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
openssl@3.5.0-r0
3.5.6-r0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
openssl@3.3.3-r0
3.3.7-r0
2
1dev/server:11.9.0cd5b12fe5471
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.