StackRadar

CVE-2026-34073

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
498
deployed by those charts
Fix available
2 of 3
affected packages

cryptography has incomplete DNS name constraint enforcement on peer names

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+69 more46.0.6498
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1no fix listed14
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
Also known as
PYSEC-2026-35

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6

Open the chart page →

6,540
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.6

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

1,636

Container images carrying it

498 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pryorda/vmware_exporter:v0.18.3e0f5ba8b7856
cryptography@36.0.2
46.0.6
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
cryptography@39.0.2
46.0.6
1
psono/psono-server:5.0.03b974b43ea03
cryptography@43.0.1
46.0.6
1
pyaephyohein/mysql2s3bk:alphafdee05f2d441
cryptography@41.0.3
46.0.6
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
cryptography@41.0.7
46.0.6
1
qonstrukt/php:8.4-v8-apache089af7925aa1
cryptography@41.0.7
46.0.6
1
redash/redash:25.8.000d813437db5
cryptography@45.0.5
46.0.6
1
redash/redash:10.0.0.b503639392753c0376
cryptography@2.8
46.0.6
1
redash/redash:26.3.0c5c9148f5c38
cryptography@46.0.5
46.0.6
1
redislabs/redisinsight:1.14.0b03ab1426d0d
cryptography@39.0.1
46.0.6
1
rommapp/romm:4.4.1b909e95d1aab
cryptography@45.0.5
46.0.6
1
rook/ceph:v1.20.72f970c425617
cryptography@36.0.1
46.0.6
1
rook/ceph:v1.19.2944a1dd70496
cryptography@36.0.1
46.0.6
1
saidsef/scapy-containerised:v2025.02f17f7c435891
cryptography@44.0.1
46.0.6
1
salehmir/jesse:1.10.101afa95f979e9
cryptography@42.0.8
46.0.6
1
saltstack/salt:3006.3e9c7906b7a5c
cryptography@41.0.3
46.0.6
1
samueldg/snappass:latest3987195edbe6
cryptography@2.8
46.0.6
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
cryptography@44.0.0
46.0.6
1
seafileltd/seafile-mc:9.0.106693911bcc40
cryptography@38.0.4
46.0.6
1
seafileltd/seafile-mc:10.0.170628f29c663
cryptography@41.0.1
46.0.6
1
seafileltd/seafile-mc:9.0.97ac833196f60
cryptography@38.0.1
46.0.6
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
cryptography@43.0.0
46.0.6
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
cryptography@3.4
46.0.6
1
semaphoreui/semaphore:v2.9.645b50bc11833f
cryptography@41.0.3
46.0.6
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
cryptography@43.0.0
46.0.6
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
cryptography@43.0.0
46.0.6
1
sissbruecker/linkding:1.35.00c5dddf0b37c
cryptography@43.0.1
46.0.6
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
cryptography@43.0.1
46.0.6
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
cryptography@2.1.4
46.0.6
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
cryptography@2.1.4
46.0.6
1
softonic/gar-exporter:0.2.1a64d6c0e0ae5
cryptography@3.2.1
46.0.6
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
cryptography@2.8
46.0.6
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
cryptography@44.0.0
46.0.6
1
stackstorm/st2actionrunner:3.888235ba70cad
cryptography@39.0.1
46.0.6
1
stackstorm/st2api:3.86f56d239d280
cryptography@39.0.1
46.0.6
1
stackstorm/st2auth:3.833ecfda16608
cryptography@39.0.1
46.0.6
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
cryptography@39.0.1
46.0.6
1
stackstorm/st2notifier:3.8f190a6212195
cryptography@39.0.1
46.0.6
1
stackstorm/st2rulesengine:3.8259503496ff9
cryptography@39.0.1
46.0.6
1
stackstorm/st2scheduler:3.8b1de2055c362
cryptography@39.0.1
46.0.6
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
cryptography@39.0.1
46.0.6
1
stackstorm/st2stream:3.81c8904a3bf67
cryptography@39.0.1
46.0.6
1
stackstorm/st2timersengine:3.81bf35bfaf00c
cryptography@39.0.1
46.0.6
1
stackstorm/st2workflowengine:3.819fdfffdbba8
cryptography@39.0.1
46.0.6
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
cryptography@2.6.1
46.0.6
1
substratusai/verba:v0.4.0-baseURL261695be635eb
cryptography@42.0.7
46.0.6
1
supabase/realtime:v2.102.3aa1c92c0cf32
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed
1
supabase/realtime:latestd3aa0c86c7b3
cryptography@43.0.0
python-cryptography@43.0.0-3+deb13u1
46.0.6
no fix listed
1
svtechnmaa/svtech_icinga2:v1.1.667be2aba9436
cryptography@40.0.2
46.0.6
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
cryptography@2.5
46.0.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.