StackRadar

CVE-2026-34073

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
610
of 17,787 indexed, latest versions
Container images
498
deployed by those charts
Fix available
2 of 3
affected packages

cryptography has incomplete DNS name constraint enforcement on peer names

Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.

Affected packageAffected versionsFixed inImages
cryptographypypi1.7.2, 1.9, 2.1.4, 2.2.2+69 more46.0.6498
python-cryptographydeb38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1no fix listed14
py3-cryptographyapk46.0.5-r046.0.7-r01
OSV records
ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
Also known as
PYSEC-2026-35

Charts affected

610 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6

Open the chart page →

5,484
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
cryptography@3.3.2
46.0.6

Open the chart page →

11,167
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
cryptography@42.0.4
46.0.6

Open the chart page →

6,540
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
cryptography@38.0.4
python-cryptography@38.0.4-3+deb12u1
46.0.6
no fix listed

Open the chart page →

8,824
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

10,286
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
cryptography@3.2.1
46.0.6

Open the chart page →

11,785
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
cryptography@35.0.0
46.0.6

Open the chart page →

2,643
zerossl-cert-managerzerossl-cert-manager0.1.01 of 2See more

zerossl-cert-manager zerossl-cert-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
andreymileshin/zerossl-issuer:v1.0.0e0825acc9e48
cryptography@44.0.2
46.0.6

Open the chart page →

569
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34073.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
cryptography@36.0.1
46.0.6

Open the chart page →

1,636

Container images carrying it

498 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
cryptography@39.0.1
46.0.6
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
cryptography@36.0.0
46.0.6
1
taigaio/taiga-back:6.4.29f97323cc150
cryptography@3.4.7
46.0.6
1
tautulli/tautulli:v2.7.7c4da15f058ea
cryptography@3.4.8
46.0.6
1
thelande/kasa_exporter:v0.2.3a1fdb8baa152
cryptography@42.0.7
46.0.6
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
cryptography@3.4.8
46.0.6
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
cryptography@3.4.8
46.0.6
1
timescale/timescaledb-ha:pg16d7db8f1085a3
cryptography@3.4.8
46.0.6
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
cryptography@3.4.8
46.0.6
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
cryptography@3.4.8
46.0.6
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
cryptography@46.0.5
46.0.6
1
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
cryptography@46.0.4
46.0.6
1
trueosiris/vrising:latest9356f98ad561
cryptography@3.4.8
46.0.6
1
tussanakorndev/kube-pod-alerts:1.0.5216fdadadf9a
cryptography@46.0.5
46.0.6
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
cryptography@3.4.8
46.0.6
1
vabene1111/recipes:2.3.50f8d061895e9
cryptography@45.0.5
46.0.6
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
cryptography@2.9.2
46.0.6
1
voltha/voltha-cli:1.6.0c4e41e92f046
cryptography@2.4.1
46.0.6
1
voltha/voltha-netconf:1.6.037f80524c207
cryptography@2.4.1
46.0.6
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
cryptography@2.4.1
46.0.6
1
voltha/voltha-tester:1.7.0655c3048a602
cryptography@2.7
46.0.6
1
voltha/voltha-voltha:1.6.0ff596b62de59
cryptography@2.4.1
46.0.6
1
wallabag/wallabag:2.4.25e4c26a7fb4a
cryptography@2.9.2
46.0.6
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
cryptography@43.0.1
46.0.6
1
wazuh/wazuh-manager:4.4.121994f40e0da
cryptography@3.3.2
46.0.6
1
wazuh/wazuh-manager:4.14.45a065930682d
cryptography@44.0.1
46.0.6
1
wazuh/wazuh-manager:4.14.3f09282d281f6
cryptography@44.0.1
46.0.6
1
weblate/weblate:3.11.3-182848df56ecd
cryptography@2.8
46.0.6
1
wiremind/pghoard:12-2019-11-264dea42c8166c
cryptography@2.8
46.0.6
1
yetiplatform/yeti:2.9.09bcbe2650a14
cryptography@44.0.2
46.0.6
1
yetiplatform/yeti:latest9c3006cedcca
cryptography@44.0.2
46.0.6
1
ygqygq2/mysql-exec-sql:latest54f30def1558
cryptography@41.0.3
46.0.6
1
zepai/knowledge-graph-mcp:v0.2.16ab0ee79926b
cryptography@45.0.4
46.0.6
1
zurdi15/romm:2.3.12db88fe44c89
cryptography@41.0.6
46.0.6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
cryptography@44.0.2
46.0.6
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
cryptography@44.0.1
46.0.6
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
cryptography@44.0.2
46.0.6
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
cryptography@41.0.7
46.0.6
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
cryptography@43.0.1
46.0.6
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
cryptography@43.0.0
46.0.6
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
cryptography@41.0.7
46.0.6
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
cryptography@41.0.7
46.0.6
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
cryptography@41.0.7
46.0.6
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
cryptography@42.0.8
46.0.6
1
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
cryptography@38.0.3
46.0.6
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
cryptography@44.0.0
46.0.6
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
cryptography@42.0.5
46.0.6
1
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
cryptography@45.0.6
46.0.6
1
ghcr.io/dask/dask:2024.1.0080150de7d86
cryptography@41.0.3
46.0.6
1
ghcr.io/dask/dask-gateway-server:2024.1.0881e7acfc5a0
cryptography@41.0.7
46.0.6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.