StackRadar

CVE-2026-34073

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
498
deployed by those charts
Fix available
2 of 3
affected packages

cryptography has incomplete DNS name constraint enforcement on peer names

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+69 more46.0.6498
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1no fix listed14
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
Also known as
PYSEC-2026-35

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6

Open the chart page →

6,540
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.6

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

1,636

Container images carrying it

498 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
milesmcc/shynet:v0.12.0e821e31140f7
cryptography@36.0.1
46.0.6
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
cryptography@44.0.3
46.0.6
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
cryptography@3.0
46.0.6
1
mozilla/syncserver:latest016162bf39d8
cryptography@2.6.1
46.0.6
1
mozilla/syncstorage-rs:0.15.893752877dced
cryptography@3.4.8
46.0.6
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
cryptography@2.3.1
46.0.6
1
mysql/mysql-cluster:8.0.20e4ea36622cdd
cryptography@2.8
46.0.6
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
cryptography@2.3
46.0.6
1
neilpeterson/get-tweet:v28b645ac1a23e
cryptography@2.2.2
46.0.6
1
neilpeterson/osba-storage-demo:latest29d229ab446e
cryptography@2.1.4
46.0.6
1
neilpeterson/process-tweet:latest39ce9f92e899
cryptography@2.2.2
46.0.6
1
netbirdio/dashboard:v2.22.215a3aab9a345
cryptography@3.3.2
46.0.6
1
netbirdio/dashboard:v2.90.101b59e1c905c9
cryptography@3.3.2
46.0.6
1
netbirdio/dashboard:v2.90.2332cc31f5f35
cryptography@3.3.2
46.0.6
1
netbirdio/dashboard:v2.13.188b5fb704a8c
cryptography@3.3.2
46.0.6
1
netboxcommunity/netbox:v3.2.83d652dca5351
cryptography@37.0.4
46.0.6
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
cryptography@42.0.7
46.0.6
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
cryptography@3.1.1
46.0.6
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
cryptography@36.0.2
46.0.6
1
nlmacamp/check_mk:latest5dbb8589f824
cryptography@2.3.1
46.0.6
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
cryptography@2.1.4
46.0.6
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
cryptography@2.3.1
46.0.6
1
openbas/caldera-server:5.1.0a277796d9724
cryptography@44.0.1
46.0.6
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
cryptography@43.0.3
46.0.6
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
cryptography@46.0.3
46.0.6
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
cryptography@45.0.6
46.0.6
1
opencsghq/label-studio:v2.5.047e22aa71870
cryptography@44.0.2
46.0.6
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
cryptography@44.0.2
46.0.6
1
opendatacube/restcube:latest91870111837c
cryptography@2.7
46.0.6
1
opendatacube/wms:latest1b90cdf68831
cryptography@2.7
46.0.6
1
opendatacube/wps:latest80df355a660b
cryptography@45.0.4
46.0.6
1
openemr/openemr:6.1.089eaa6d9a4e3
cryptography@36.0.2
46.0.6
1
openmined/syft-backend:0.9.5b72f74a68b32
cryptography@44.0.1
46.0.6
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
cryptography@38.0.3
46.0.6
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
cryptography@3.4.6
46.0.6
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
cryptography@3.4.6
46.0.6
1
openvpn/openvpn-as:latest2253c10ec652
cryptography@41.0.7
46.0.6
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
cryptography@2.5
46.0.6
1
openzaak/open-notificaties:1.3.02e65313b9b10
cryptography@3.4.8
46.0.6
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
cryptography@3.4.8
46.0.6
1
pangeo/base-notebook:2024.01.155fbe688a4f80
cryptography@41.0.3
46.0.6
1
percona/pmm-server:3.9.1003f9c25f842
cryptography@36.0.1
46.0.6
1
platzio/backend:v0.6.5d5e5972f344b
cryptography@44.0.3
46.0.6
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
cryptography@2.8
46.0.6
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
cryptography@41.0.3
46.0.6
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
cryptography@43.0.0
46.0.6
1
prompve/prometheus-pve-exporter:3.8.2e3d501a82df5
cryptography@46.0.5
46.0.6
1
prompve/prometheus-pve-exporter:3.4.2fcf041f0c24d
cryptography@42.0.4
46.0.6
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
cryptography@2.9.2
46.0.6
1
pryorda/vmware_exporter:v0.18.479925e63e59f
cryptography@38.0.1
46.0.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.