StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,518
of 17,787 indexed, latest versions
Container images
2,896
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,518 of 17,787 indexed charts deploy, on 2,896 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,662
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0904
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5330
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,518 by stars
ChartLatestAffected imagesRadar Score
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

13,031
dnation-kubernetes-jsonnet-translatordnationcloud2.0.11 of 1See more

dnation-kubernetes-jsonnet-translator dnationcloud 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,626
dnation-kubernetes-monitoringdnationcloud3.0.21 of 1See more

dnation-kubernetes-monitoring dnationcloud 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,626
dnation-kubernetes-monitoring-stackdnationcloud4.0.26 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

6 of the 17 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dnationcloud/kubernetes-jsonnet-translator:2.0.178fed4f3c130
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
kiwigrid/k8s-sidecar:1.28.04166a019eeaf
openssl@3.3.2-r0
3.3.7-r0
library/memcached:1.6.32-alpine0a27d9d5084f
openssl@3.3.2-r1
3.3.7-r0
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
openssl@3.3.3-r0
3.3.7-r0
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

21,455
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
openssl@1.1.1-1ubuntu2.1~18.04.4
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

8,991
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

3,030
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,506
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

2,862
dominodomino-iisasVerified publisher0.3.13 of 3See more

domino domino-iisas 0.3.1

3 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
ghcr.io/iisas/domino-frontend:k8s8e53861be292
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
ghcr.io/iisas/domino-rest:latest3009350bfc11
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

10,307
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
openssl@1:3.2.2-6.el9_5
1:3.5.5-3.el9_8

Open the chart page →

3,166
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.23

Open the chart page →

24,975
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,201
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,269
seleniumdoubanVerified publisher1.3.21 of 1See more

selenium douban 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,831
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.03 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

24,714
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
openssl@1:3.0.1-43.el9_0
1:3.5.5-3.el9_8
quay.io/keycloak/keycloak:20.0054ef67eb7da
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

55,988
drogue-cloud-examplesdrogue-iotVerified publisher0.7.114 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

4 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.23
ghcr.io/ctron/kubectl:1.25e37d61b5277c
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
openssl@1:1.1.1k-5.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

30,759
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6

Open the chart page →

6,914
duckdb-uiduckdb-ui0.5.21 of 1See more

duckdb-ui duckdb-ui 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

4,283
cloudflaredduck-helm1.1.31 of 1See more

cloudflared duck-helm 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

1,442
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
openssl@3.5.1-1
3.5.5-1~deb13u2

Open the chart page →

3,426
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-28390.

Open the chart page →

4,253
duplicacyduplicacy0.1.22 of 2See more

duplicacy duplicacy 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
openssl@3.5.5-r0
3.5.6-r0
drumsergio/duplicacy-exporter:0.3.4ca3476077215
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,413
kubernetes-database-scalerdvdlevanonVerified publisher0.1.21 of 1See more

kubernetes-database-scaler dvdlevanon 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
openssl@3.5.0-r0
3.5.6-r0

Open the chart page →

1,022
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15

Open the chart page →

19,820
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

973
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

9,251
bitcoinddysnixVerified publisher0.4.31 of 2See more

bitcoind dysnix 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

1,970
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

2,513
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,593
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

13,422
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

3,889
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
openssl@1:1.1.1k-6.el8_5
1:1.1.1k-17.el8_6

Open the chart page →

11,482
openfaas2eclipse-aeriosVerified publisher12.0.52 of 6See more

openfaas2 eclipse-aerios 12.0.5

2 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
openssl@3.3.2-r4
3.3.7-r0
ghcr.io/openfaas/gateway:0.27.1382b15393116e
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

6,678
orion-ldeclipse-aeriosVerified publisher1.0.02 of 2See more

orion-ld eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
fiware/orion-ld:1.10.03c490a746f65
openssl@1:1.1.1k-14.el8_6
1:1.1.1k-17.el8_6
library/mongo:7.0.12ae1cf99fa7bf
openssl@3.0.2-0ubuntu1.17
3.0.2-0ubuntu1.23

Open the chart page →

9,805
self-awarenesseclipse-aeriosVerified publisher1.4.41 of 2See more

self-awareness eclipse-aerios 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
openssl@3.5.4-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

2,195
trustmanagereclipse-aeriosVerified publisher1.0.01 of 1See more

trustmanager eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2

Open the chart page →

1,907
marblerunedgelesssysVerified publisher1.9.21 of 1See more

marblerun edgelesssys 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,850
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
openssl@1.1.1-1ubuntu2.1~18.04.13
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

10,995
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

20,233
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,344
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

5,150
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
openssl@3.3.2-r0
3.3.7-r0

Open the chart page →

1,284
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
openssl@3.3.4-r0
3.3.7-r0

Open the chart page →

1,663
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,333
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

4,046
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

4,033
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

4,033
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6

Open the chart page →

4,033
eggybyte-chaineggybyte-hcr1.0.01 of 1See more

eggybyte-chain eggybyte-hcr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.6-r0

Open the chart page →

806

Container images carrying it

2,896 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
altinity/clickhouse-operator:0.19.07a85f522c5bc
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
altinity/metrics-exporter:0.20.01a46d104406d
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
openssl@3.3.3-r0
3.3.7-r0
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
openssl@3.3.3-r0
3.3.7-r0
1
anchore/anchore-engine:v0.10.0bde9eedf639d
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
openssl@1:1.1.1c-2.el8_1.1
1:1.1.1k-17.el8_6
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
andrianrf/backoffice:latest047a7837651e
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
1
andrianrf/backoffice-be:latest6036614803d4
openssl@1:3.0.7-6.el9_2
1:3.5.5-3.el9_8
1
andrianrf/iso-server:latest7da47f525c7d
openssl@1:3.0.7-6.el9_2
1:3.5.5-3.el9_8
1
anguda/ant-media:2.5c435285fc241
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm3
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
openssl@3.0.11-1~deb12u1
3.0.19-1~deb12u2
1
anujdatar/cups:25.07.01685df04a643b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
1
apache/activemq-artemis:2.44.00305c26f19ed
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
1
apache/activemq-artemis:2.37.0bae523439ee3
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.9
1
apache/airflow:2.8.4-python3.964e58748b6b9
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
1
apache/airflow:2.8.1e5560ad0b86e
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
apache/camel-k:1.10.43bb13d14f64a
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.23
1
apache/hertzbeat:1.8.075d48a62748f
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.9
1
apache/iotdb:0.13.3-nodeafa47bf1692a
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
1
apache/kafka:4.1.0bff074a5d005
openssl@3.5.2-r0
3.5.6-r0
1
apache/kafka:3.9.0fbc7d7c428e3
openssl@3.3.2-r1
3.3.7-r0
1
apache/kafka-native:4.1.09a9d16e60894
openssl@3.5.1-r0
3.5.6-r0
1
apache/nifi-registry:1.27.063b8e3e40742
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.23
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3
1
apachepulsar/pulsar:3.0.79c9947de139d
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
1
apachepulsar/pulsar:2.9.0d056c89b7131
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
1
apachepulsar/pulsar:2.8.2d538416d5afe
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3
1
apache/ranger:2.7.076c176e8a0e4
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
1
apache/rocketmq:5.3.0434d8398f996
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.9
1
apache/rocketmq-exporter:0.0.2c8fb51195444
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
1
apache/skywalking-oap-server:9.2.0133d35d2c263
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3
1
apache/skywalking-ui:9.2.0295f1dc87d98
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23
1
apache/skywalking-ui:8.9.180530f0308a5
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3
1
apache/superset:4.0.1ab9467fd712c
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
1
apache/tika:2.9.0.092d055a84e9e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.23
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
openssl@3.5.1-1
3.5.5-1~deb13u2
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
openssl@3.3.2-r0
3.3.7-r0
1
apecloud/gemini-scheduler:0.1.15832d1a9097a
openssl@3.3.1-r3
3.3.7-r0
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
openssl@1:3.5.1-5.el9_7
1:3.5.5-3.el9_8
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
openssl@1:1.1.1k-9.el8_7
1:1.1.1k-17.el8_6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.