StackRadar

CVE-2026-34073

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
498
deployed by those charts
Fix available
2 of 3
affected packages

cryptography has incomplete DNS name constraint enforcement on peer names

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+69 more46.0.6498
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1no fix listed14
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
Also known as
PYSEC-2026-35

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6

Open the chart page →

6,540
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.6

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

1,636

Container images carrying it

498 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
cryptography@44.0.3
46.0.6
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
cryptography@44.0.3
46.0.6
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
cryptography@37.0.4
46.0.6
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
cryptography@41.0.7
46.0.6
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
cryptography@44.0.3
46.0.6
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
cryptography@44.0.0
46.0.6
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
cryptography@42.0.7
46.0.6
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
cryptography@42.0.7
46.0.6
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
cryptography@43.0.1
46.0.6
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
cryptography@46.0.0
46.0.6
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
cryptography@46.0.5
46.0.6
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
cryptography@46.0.3
46.0.6
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
cryptography@44.0.0
46.0.6
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
cryptography@43.0.1
46.0.6
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
cryptography@44.0.0
46.0.6
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
cryptography@39.0.1
46.0.6
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
cryptography@38.0.4
python-cryptography@38.0.4-3
46.0.6
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
cryptography@43.0.3
46.0.6
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
cryptography@42.0.4
46.0.6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.76e43ba0bd009
cryptography@42.0.5
46.0.6
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
cryptography@45.0.6
46.0.6
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
cryptography@43.0.3
46.0.6
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
cryptography@43.0.1
46.0.6
1
quay.io/ansible/awx-operator:2.19.17302e0c8e5a7
cryptography@41.0.7
46.0.6
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
cryptography@43.0.0
46.0.6
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
cryptography@3.2.1
46.0.6
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
cryptography@37.0.2
46.0.6
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
cryptography@41.0.3
46.0.6
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
cryptography@41.0.7
46.0.6
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
cryptography@45.0.2
46.0.6
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
cryptography@46.0.3
46.0.6
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
cryptography@36.0.2
46.0.6
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
cryptography@41.0.5
46.0.6
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
cryptography@44.0.2
46.0.6
1
quay.io/netscaler/netscaler-k8s-ingress-controller:4.1.1755b12c2a8440
cryptography@43.0.1
46.0.6
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
cryptography@38.0.1
46.0.6
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
cryptography@46.0.3
46.0.6
1
quay.io/ortelius/ms-dep-pkg-cud:main-v10.0.1670-g9abe110c0c881b509a
cryptography@46.0.3
46.0.6
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
cryptography@46.0.3
46.0.6
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
cryptography@46.0.3
46.0.6
1
quay.io/ortelius/ms-scorecard:main-v10.0.1276-g966a8a43337e52fdd4
cryptography@46.0.3
46.0.6
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
cryptography@46.0.3
46.0.6
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
cryptography@46.0.3
46.0.6
1
quay.io/stackgres/operator:1.19.1f241b0b20326
cryptography@43.0.1
46.0.6
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
cryptography@46.0.5
46.0.6
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
cryptography@3.4.8
46.0.6
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
cryptography@3.4.8
46.0.6
1
registry.gitlab.com/xrow-public/helm-smtp/postfix:1.3.37eea4f0883dd
cryptography@46.0.3
46.0.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.