StackRadar

CVE-2026-28390

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,504
of 17,781 indexed, latest versions
Container images
2,879
deployed by those charts
Fix available
4 of 5
affected packages

Red Hat Security Advisory: openssl security update

Carried by container images the latest versions of 2,504 of 17,781 indexed charts deploy, on 2,879 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.2g-1ubuntu4.5, 1.0.2g-1ubuntu4.6, 1.0.2g-1ubuntu4.8, 1.0.2g-1ubuntu4.9+94 more1.0.2g-1ubuntu4.20+esm15, 1.1.1-1ubuntu2.1~18.04.23+esm8, 1.1.1f-1ubuntu2.24+esm3, 3.0.2-0ubuntu1.23+4 more1,652
opensslapk3.1.4-r2, 3.2.0-r0, 3.3.0-r2, 3.3.1-r0+22 more3.3.7-r0, 3.5.6-r0, 3.6.2-r0898
opensslrpm1:1.1.1-8.el8, 1:1.1.1c-2.el8_1.1, 1:1.1.1c-15.el8, 1:1.1.1c-19.el8_2+31 more1:1.1.1k-17.el8_6, 1:1.1.1k-17.el8_10, 1:3.5.5-3.el9_8, 3.3.5-5329
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm415
OSV records
ALPINE-CVE-2026-28390CGA-8g7f-wxpv-r4x7DEBIAN-CVE-2026-28390RHSA-2026:22312RHSA-2026:38503RLSA-2026:22312RLSA-2026:38503UBUNTU-CVE-2026-28390AZL-82070ECHO-9d88-691e-4e0f
Also known as
CGA-9w5g-cc3c-h84f, CGA-c8f9-m6q4-pf8c, CGA-r9mm-rw3c-wqh3, RHSA-2026:38804, RHSA-2026:38805, RHSA-2026:43513, USN-8155-1, USN-8155-2

Charts affected

2,504 by stars
ChartLatestAffected imagesRadar Score
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

18,376
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.9

Open the chart page →

5,670
gethdysnixVerified publisher1.1.21 of 1See more

geth dysnix 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ethereum/client-go:v1.14.8886ec69b35b0
openssl@3.3.1-r3
3.3.7-r0

Open the chart page →

1,624
glpieftechcombr-glpiVerified publisher2.12.02 of 5See more

glpi eftechcombr-glpi 2.12.0

2 of the 5 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
eftechcombr/glpi:nginx-12.0.0-rc1372f0bd43e15
openssl@3.3.3-r0
3.3.7-r0
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

4,341
elchi-stackelchi1.13.04 of 10See more

elchi-stack elchi 1.13.0

4 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.81ffa82edee00
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm3
envoyproxy/envoy:v1.33.056da5afd7df3
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.23
grafana/grafana:12.2.074144189b384
openssl@3.5.1-r0
3.5.6-r0
library/mongo:6.0.12646902910d6a
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23

Open the chart page →

15,383
enavenav-service-architectureVerified publisher0.0.71 of 10See more

enav enav-service-architecture 0.0.7

1 of the 10 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
apache/kafka:3.9.0fbc7d7c428e3
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

15,860
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
openssl@1:1.1.1g-15.el8_3
1:1.1.1k-17.el8_6
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

31,510
kubevirtencircle360-ossVerified publisher0.2.11 of 1See more

kubevirt encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/kubevirt/virt-operator:v1.7.037d2ef21e3e5
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

850
eoapieoapiOfficialVerified publisher0.16.22 of 7See more

eoapi eoapi 0.16.2

2 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
openssl@3.5.4-r0
3.5.6-r0
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

6,250
copypartyernail-copyparty2.0.01 of 1See more

copyparty ernail-copyparty 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
copyparty/ac:1.19.200a0a8605062c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,685
scoolderudikaVerified publisher0.3.01 of 1See more

scoold erudika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
erudikaltd/scoold:1.66.0949c56b57e8f
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,605
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23

Open the chart page →

3,048
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

1,442
lighthouseethereum-helm-chartsVerified publisher1.1.91 of 2See more

lighthouse ethereum-helm-charts 1.1.9

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
sigp/lighthouse:latest9a62bb870545
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

1,548
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
openssl@3.0.13-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

11,458
vulnz-nvd-mirroreugen1.0.01 of 1See more

vulnz-nvd-mirror eugen 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,675
evccevccVerified publisher1.0.471 of 1See more

evcc evcc 1.0.47

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
evcc/evcc:0.300.8ddf2a25afce5
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

1,181
mcrouterevryfs-ossVerified publisher0.4.01 of 2See more

mcrouter evryfs-oss 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

6,500
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

4,333
atlas-cmmsf3k-techVerified publisher0.151.51 of 4See more

atlas-cmms f3k-tech 0.151.5

1 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

5,291
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2

Open the chart page →

1,664
recaptcha-v3-verifierf3k-techVerified publisher1.110.01 of 1See more

recaptcha-v3-verifier f3k-tech 1.110.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
openssl@3.0.17-1~deb12u3
3.0.19-1~deb12u2

Open the chart page →

1,208
fastapi-microservice-appfast-api-microservice-app1.3.04 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

4 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
library/mongo:7.0b6421fd6d1c5
openssl@3.0.2-0ubuntu1.26
no fix listed
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
omkara25/simple-microservice-app-user-service:v2d62cba548580
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2

Open the chart page →

9,562
featurehubfeaturehub4.1.63 of 7See more

featurehub featurehub 4.1.6

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
featurehub/dacha2:1.9.1c8d5551b5e40
openssl@3.3.3-r0
3.3.7-r0
featurehub/edge:1.9.198ad426737f6
openssl@3.3.3-r0
3.3.7-r0
featurehub/mr:1.9.1477d8bf771a9
openssl@3.3.3-r0
3.3.7-r0

Open the chart page →

8,240
zabbix-server-mysqlfermosit3.0.23 of 4See more

zabbix-server-mysql fermosit 3.0.2

3 of the 4 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

12,840
ferriskeyferriskey0.7.21 of 3See more

ferriskey ferriskey 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/ferriskey/ferriskey-api:0.7.228b6adba10f8
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2

Open the chart page →

3,262
flink-operatorflink-operator0.1.11 of 2See more

flink-operator flink-operator 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
openssl@1.1.1-1ubuntu2.1~18.04.5
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm8
1.0.2n-1ubuntu5.13+esm4

Open the chart page →

12,908
memosgabe565Verified publisher0.17.01 of 1See more

memos gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/usememos/memos:0.24.04723d86e6797
openssl@3.3.2-r4
3.3.7-r0

Open the chart page →

1,323
garage-uigarage-uiVerified publisher0.12.11 of 1See more

garage-ui garage-ui 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
noooste/garage-ui:v0.12.10b68a9237da6
openssl@3.5.5-r0
3.5.6-r0

Open the chart page →

763
gateboardgateboard1.12.51 of 1See more

gateboard gateboard 1.12.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
udhos/gateboard:1.12.53acc0e7599bf
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,463
gateboard-discoverygateboard1.9.51 of 1See more

gateboard-discovery gateboard 1.9.5

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
udhos/gateboard-discovery:1.9.55567c9363c4c
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,190
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

17,377
games-on-whalesgeek-cookbookVerified publisher1.8.23 of 7See more

games-on-whales geek-cookbook 1.8.2

3 of the 7 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

35,305
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,653
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

11,662
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

11,553
ombigeek-cookbookVerified publisher11.5.21 of 1See more

ombi geek-cookbook 11.5.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

5,136
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8

Open the chart page →

8,029
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

11,558
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

10,231
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.23

Open the chart page →

13,025
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

15,856
tdarrgeek-cookbookVerified publisher4.6.22 of 2See more

tdarr geek-cookbook 4.6.2

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
haveagitgat/tdarr_node:2.00.101e3f9328327d
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

31,000
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
openssl@3.5.5-1~deb13u1
3.5.5-1~deb13u2

Open the chart page →

4,879
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

7,660
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.33 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

3 of the 9 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm3
confluentinc/cp-kafka:7.4.4c0224a1adf7a
openssl@1:1.1.1k-12.el8_9
1:1.1.1k-17.el8_6
library/postgres:15.38775adb39f0d
openssl@3.0.9-1
3.0.19-1~deb12u2

Open the chart page →

15,562
geo-checkergeo-checkerVerified publisher5.0.01 of 1See more

geo-checker geo-checker 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
ymuski/geo-checker:5.0.05ba7fd8c7bdc
openssl@3.5.4-r0
3.5.6-r0

Open the chart page →

1,455
leantimegissilabs1.3.02 of 2See more

leantime gissilabs 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
leantime/leantime:3.3.3ad4bfb0699d3
openssl@3.3.2-r1
3.3.7-r0
library/mariadb:10.6.218a16204dc96c
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3

Open the chart page →

6,416
gitea-sonarqube-botgitea-sonarqube-botOfficialVerified publisher0.4.01 of 1See more

gitea-sonarqube-bot gitea-sonarqube-bot 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
openssl@3.3.2-r1
3.3.7-r0

Open the chart page →

1,145
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-28390.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.9

Open the chart page →

3,518

Container images carrying it

2,879 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm3
79
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm8
79
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm8
13
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.6-r0
13
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
11
oomk8s/readiness-check:2.0.2875814cc853d
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
11
codeurjc/weatherservice:v1.0b9e2f7234349
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
10
library/mongo:5.0.6-focal8e70544b6c76
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm3
10
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
10
codeurjc/server:v1.0310bea5b1ee7
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
8
library/rabbitmq:3.13-management:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.9
8
library/kong:3.6a42d2b4503e7
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.23
7
bitnamilegacy/rabbitmq:4.1.3:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2
6
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
6
curlimages/curl:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.6-r0
6
library/mariadb:10:10.11ce66c7be32a0
openssl@3.0.2-0ubuntu1.26
no fix listed
6
oomk8s/readiness-check:2.0.07daa08b81954
openssl@1.0.2g-1ubuntu4.10
1.0.2g-1ubuntu4.20+esm15
6
pnnlmiscscripts/anaconda9:1714885940.021839-nginx-1cfbc9b70cbf8
openssl@3.3.2-r1
3.3.7-r0
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
6
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
6
alpine/kubectl:1.34.18413f8890d19
openssl@3.5.4-r0
3.5.6-r0
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
openssl@3.0.11-1~deb12u2
3.0.19-1~deb12u2
5
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
5
keelhq/keel:latest73714afb4443
openssl@3.3.2-r0
3.3.7-r0
5
library/memcached:1.6.39-alpinec8503d4491ed
openssl@3.5.4-r0
3.5.6-r0
5
library/mongo:4.44be76f674fc4
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
5
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
5
library/redis:7.4.2-alpine:7.4.2-alpine3.2102419de7eddf
openssl@3.3.3-r0
3.3.7-r0
5
solsson/kafka:latest41e5d8f6f290
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm3
5
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
openssl@3.5.5-r0
3.5.6-r0
5
artifacthub/postgres:latest4fd34fa635cc
openssl@3.5.1-1
3.5.5-1~deb13u2
4
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
4
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
openssl@3.0.17-1~deb12u1
3.0.19-1~deb12u2
4
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
3.0.19-1~deb12u2
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
3.0.19-1~deb12u2
4
bitnamilegacy/rabbitmq:4.1.2:4.1.2-debian-12-r1fac502149c40
openssl@3.0.16-1~deb12u1
3.0.19-1~deb12u2
4
cloudflare/cloudflared:2026.3.06b599ca3e974
openssl@3.5.4-1~deb13u2
3.5.5-1~deb13u2
4
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
no fix listed
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm15
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm15
4
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.23
4
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm3
4
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm8
4
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm8
4
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
3.0.19-1~deb12u2
4
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
3.5.5-1~deb13u2
4
library/rabbitmq:3.13-management-alpine:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.6-r0
4
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.23
4
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.23
4
mastercloudapps/server:v2.23f3d24dfe2686
openssl@1:1.1.1k-7.el8_6
1:1.1.1k-17.el8_6
4

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.