StackRadar

CVE-2026-34073

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
498
deployed by those charts
Fix available
2 of 3
affected packages

cryptography has incomplete DNS name constraint enforcement on peer names

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+69 more46.0.6498
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1no fix listed14
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
Also known as
PYSEC-2026-35

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6

Open the chart page →

6,540
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.6

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

1,636

Container images carrying it

498 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
anchore/anchore-engine:v0.10.0bde9eedf639d
cryptography@3.3.2
46.0.6
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
cryptography@2.9.2
46.0.6
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
cryptography@41.0.7
46.0.6
1
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
cryptography@3.3.2
46.0.6
1
apache/airflow:2.8.4-python3.964e58748b6b9
cryptography@41.0.7
46.0.6
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
cryptography@42.0.8
46.0.6
1
apache/airflow:2.8.1e5560ad0b86e
cryptography@41.0.7
46.0.6
1
apache/hertzbeat:1.8.075d48a62748f
cryptography@41.0.7
46.0.6
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
cryptography@41.0.7
46.0.6
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
cryptography@3.4.7
46.0.6
1
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6
1
apache/tika:latest-full80072bb73dd3
cryptography@46.0.5
46.0.6
1
apache/tika:3.2.2.0-fullffab324253ed
cryptography@43.0.0
46.0.6
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
cryptography@41.0.7
46.0.6
1
appwrite/appwrite:1.9.01aaa70127114
cryptography@46.0.5
py3-cryptography@46.0.5-r0
46.0.6
46.0.7-r0
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
cryptography@39.0.2
46.0.6
1
aristidetm/basic-notebook:3.6.5469dbc951224
cryptography@42.0.8
46.0.6
1
aristidetm/k8s-hub:3.3.7ccb516cb8474
cryptography@42.0.5
46.0.6
1
assistiot/authorization_db:latestc3adbab6a3e7
cryptography@41.0.3
46.0.6
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
cryptography@3.3.2
46.0.6
1
baserow/backend:1.31.1e0b3c8130b91
cryptography@42.0.8
46.0.6
1
baserow/baserow:1.30.1df0c42eb67e8
cryptography@42.0.8
46.0.6
1
behnambm/docker-sample:v1bd3ad88afff9
cryptography@41.0.7
46.0.6
1
benbusby/whoogle-search:0.5.4f77f7e6e4ad2
cryptography@3.3.2
46.0.6
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
cryptography@43.0.3
46.0.6
1
bmeares/meerschaum:2.8.48e9c5bacaa82
cryptography@44.0.0
46.0.6
1
bnjbvr/kresus:0.22.137e216b182c8
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed
1
boky/postfix:5.1.0aafc77238423
cryptography@46.0.3
46.0.6
1
camerahub/camerahub:0.36.23a5af37dd6e1b
cryptography@40.0.2
46.0.6
1
camptocamp/ekorre:0.1.035c91d5fda04
cryptography@2.8
46.0.6
1
camptocamp/pghoard:10bff736b15623
cryptography@2.3.1
46.0.6
1
camptocamp/snow-webhook:latest2924b43dbf40
cryptography@2.6.1
46.0.6
1
castai/hibernate:v0.14da62858c8381
cryptography@43.0.3
46.0.6
1
cdignam/kodiak:v0.54.05a6a55b39cee
cryptography@3.4.8
46.0.6
1
ceph/daemon:latest-nautilus90f30824a96e
cryptography@1.7.2
46.0.6
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
cryptography@2.6.1
46.0.6
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
cryptography@46.0.5
46.0.6
1
chorss/docker-pgadmin4:4.115c549cacb8ab
cryptography@2.7
46.0.6
1
cleveritcz/opencve:1.5.0c75c1636e0b7
cryptography@42.0.5
46.0.6
1
cloudve/janis-terminal:latestaf56e77ca587
cryptography@2.1.4
46.0.6
1
cloudve/ttyd:latestd79c1c5881c0
cryptography@2.9.2
46.0.6
1
codecov/self-hosted-api:24.4.10475cb1c3136
cryptography@42.0.0
46.0.6
1
codecov/self-hosted-worker:24.4.1837f546b479b
cryptography@42.0.5
46.0.6
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
cryptography@3.3.1
46.0.6
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
cryptography@3.3.1
46.0.6
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
cryptography@3.4.8
46.0.6
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
cryptography@41.0.7
46.0.6
1
confluentinc/cp-kafka:7.5.1dc9b972db002
cryptography@41.0.4
46.0.6
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
cryptography@3.3.1
46.0.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.