StackRadar

CVE-2026-34073

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
498
deployed by those charts
Fix available
2 of 3
affected packages

cryptography has incomplete DNS name constraint enforcement on peer names

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+69 more46.0.6498
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1no fix listed14
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
Also known as
PYSEC-2026-35

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6

Open the chart page →

6,540
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.6

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

1,636

Container images carrying it

498 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
galaxy/cloudman-server:lateste5c265fe9fcd
cryptography@38.0.1
46.0.6
1
galaxy/galaxy-init:v18.010267bad550e6
cryptography@2.2.2
46.0.6
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
cryptography@44.0.3
46.0.6
1
gethue/hue:4.11.011b649636e68
cryptography@36.0.1
46.0.6
1
gethue/hue:4.10.05702b2c37ff9
cryptography@3.3.2
46.0.6
1
gethue/hue:latest7d5c1b9f8a79
cryptography@42.0.8
46.0.6
1
getsentry/sentry-kubernetes:latest6ac37974fd2a
cryptography@2.6.1
46.0.6
1
gluufederation/opendj:4.3.0_011a1128b28b95
cryptography@3.3.2
46.0.6
1
goofball222/pritunl:1.30.3070.5943c0743701d4
cryptography@3.4.7
46.0.6
1
goofball222/pritunl:1.32.3602.807bf26032dfce
cryptography@38.0.4
46.0.6
1
gpappsoft/privacyidea-docker:3.12.2af7841adad26
cryptography@44.0.2
46.0.6
1
grafana/oncall:v1.16.5499851658393
cryptography@44.0.1
46.0.6
1
hansehe/locust:1.1.0bc8e45262bc4
cryptography@44.0.2
46.0.6
1
hayk96/alerta-web:9.0.486377705e9e3
cryptography@44.0.0
46.0.6
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
cryptography@39.0.2
46.0.6
1
heartexlabs/label-studio:latestaa461572e8f9
cryptography@46.0.5
46.0.6
1
helga09/my_sql_shoes:v1.1.1a03657d97897
cryptography@37.0.2
46.0.6
1
hhyo/archery:v1.9.11aa41843419e
cryptography@38.0.1
46.0.6
1
hjacobs/kube-downscaler:23.2.05d328c003efe
cryptography@39.0.1
46.0.6
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
cryptography@41.0.1
46.0.6
1
hjacobs/kube-ops-view:23.5.0a4fae38f93d7
cryptography@40.0.2
46.0.6
1
hjacobs/kube-resource-report:21.2.145f93491c434
cryptography@3.4.1
46.0.6
1
hjacobs/kube-resource-report:22.11.0c173cd02f5af
cryptography@38.0.4
46.0.6
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
cryptography@41.0.1
46.0.6
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
cryptography@3.1.1
46.0.6
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
cryptography@37.0.2
46.0.6
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
cryptography@41.0.4
46.0.6
1
homeassistant/home-assistant:2023.12.48d000332b09b
cryptography@41.0.7
46.0.6
1
i4trust/activation-service:2.2.09f3719176893
cryptography@41.0.1
46.0.6
1
improwised/erpnext-worker:v13.4.197280b55cbd4
cryptography@3.4.7
46.0.6
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6
1
jertel/elastalert2:2.2.34dcc0ef93efc
cryptography@35.0.0
46.0.6
1
jmferrer/azure-devops-agent:latest030f68ec6998
cryptography@2.8
46.0.6
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
cryptography@3.3.2
46.0.6
1
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
cryptography@41.0.3
46.0.6
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
cryptography@3.2.1
46.0.6
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
cryptography@3.4.7
46.0.6
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
cryptography@41.0.3
46.0.6
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
cryptography@3.1.1
46.0.6
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
cryptography@3.1.1
46.0.6
1
kennethreitz/httpbin:latest599fe5e50731
cryptography@2.1.4
46.0.6
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
cryptography@41.0.3
46.0.6
1
kiwigrid/k8s-sidecar:0.0.186eb52513d59e
cryptography@2.7
46.0.6
1
kiwigrid/k8s-sidecar:0.0.16899ccd0b1f54
cryptography@2.6.1
46.0.6
1
knspar/phronetis:0.1.4609499d2dc91a
cryptography@45.0.4
46.0.6
1
kobotoolbox/kobocat:2.022.24ab15679454415
cryptography@36.0.2
46.0.6
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
cryptography@36.0.2
46.0.6
1
kubegems/juicefs-mount:ce-v1.1.010abb76892b8
cryptography@2.6.1
46.0.6
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
cryptography@45.0.7
46.0.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.