StackRadar

CVE-2026-28755

Medium

Advisory

Published 24 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
4 of 4
affected packages

NGINX ngx_stream_ssl_module vulnerability

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
nginxapk1.28.0-r3, 1.28.1-r1, 1.28.2-r11.28.3-r07
nginxdeb1.24.0-2ubuntu7.1, 1.24.0-2ubuntu7.51.24.0-2ubuntu7.72
nginx-mainlineapk1.27.4-r0, 1.27.4-r21.29.7-r02
nginxbitnami1.28.0-01.28.31
OSV records
ALPINE-CVE-2026-28755BIT-nginx-2026-28755CGA-mxj8-2635-78w6UBUNTU-CVE-2026-28755
Also known as
BIT-nginx-gateway-2026-28755, CGA-x79f-gwx5-3g4c, USN-8210-1

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
zabbixzabbix-communityVerified publisher7.1.01 of 5See more

zabbix zabbix-community 7.1.0

1 of the 5 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nginx@1.24.0-2ubuntu7.5
1.24.0-2ubuntu7.7

Open the chart page →

13,664
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
nginx@1.28.0-0
1.28.3

Open the chart page →

52,635
zabbix-server-mysqlfermosit3.0.21 of 4See more

zabbix-server-mysql fermosit 3.0.2

1 of the 4 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
nginx@1.24.0-2ubuntu7.1
1.24.0-2ubuntu7.7

Open the chart page →

12,840
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
nginx@1.28.2-r1
1.28.3-r0

Open the chart page →

3,157
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
nginx@1.28.0-r3
1.28.3-r0

Open the chart page →

10,897
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
nginx@1.28.0-r3
1.28.3-r0

Open the chart page →

1,811
kubecostradar-baseVerified publisher1.0.01 of 7See more

kubecost radar-base 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
nginx-mainline@1.27.4-r0
1.29.7-r0

Open the chart page →

9,355
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
nginx@1.28.0-r3
1.28.3-r0

Open the chart page →

4,499
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
nginx@1.28.2-r1
1.28.3-r0

Open the chart page →

1,802
tabixsinextraVerified publisher0.2.21 of 1See more

tabix sinextra 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
nginx@1.28.0-r3
1.28.3-r0

Open the chart page →

1,249
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
nginx-mainline@1.27.4-r2
1.29.7-r0

Open the chart page →

7,901
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-28755.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
nginx@1.28.1-r1
1.28.3-r0

Open the chart page →

2,043

Container images carrying it

12 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
nginx@1.28.2-r1
1.28.3-r0
1
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
nginx@1.28.0-0
1.28.3
1
heartexlabs/label-studio:latestaa461572e8f9
nginx@1.28.2-r1
1.28.3-r0
1
jeboehm/mailserver-web:5.0.929da13edf5aa8
nginx@1.28.0-r3
1.28.3-r0
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
nginx@1.28.1-r1
1.28.3-r0
1
vabene1111/recipes:2.3.50f8d061895e9
nginx@1.28.0-r3
1.28.3-r0
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
nginx@1.24.0-2ubuntu7.1
1.24.0-2ubuntu7.7
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nginx@1.24.0-2ubuntu7.5
1.24.0-2ubuntu7.7
1
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
nginx-mainline@1.27.4-r2
1.29.7-r0
1
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
nginx-mainline@1.27.4-r0
1.29.7-r0
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
nginx@1.28.0-r3
1.28.3-r0
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
nginx@1.28.0-r3
1.28.3-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.