StackRadar

CVE-2026-35189

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,961
of 17,985 indexed, latest versions
Container images
2,998
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,961 of 17,985 indexed charts deploy, on 2,998 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,700
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2298
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-35189DEBIAN-CVE-2026-35189UBUNTU-CVE-2026-35189ECHO-312d-f531-8c85
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 4 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,961 by stars
ChartLatestAffected imagesRadar Score
ceph-exporterygqygq2Verified publisher1.0.01 of 1See more

ceph-exporter ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
digitalocean/ceph_exporter:latest3ba058e9a48d
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

6,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,894
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

2,577
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,887
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,901
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

637
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,836
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,003
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,129
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

9,659
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
openssl@3.0.2-0ubuntu1.30
no fix listed

Open the chart page →

6,257

Container images carrying it

2,998 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
library/postgres:17.10ebba4f4de37f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
library/postgres:17.5-bookwormfbcea1bd13b6
openssl@3.0.17-1~deb12u2
no fix listed
1
library/python:3.104379c343a93c
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/python:3.8d41127070014
openssl@3.0.14-1~deb12u2
no fix listed
1
library/python:3.11-slimda047cb8f9d1
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/python:3.9da5aee29682d
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u3
1
library/python:3.12-slimf77ac9e44ae9
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/rabbitmq:3.12.100742852455ad
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.30
1
library/rabbitmq:4.3.5078107e03637
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
library/rabbitmq:3.11.5-management1b0f675d2f24
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm6
1
library/rabbitmq:4.1.8-management3574a8edaca3
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
library/rabbitmq:3.7-managementb6dd45cc35b3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11
1
library/rabbitmq:4-management:managementddc75301edf5
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
library/rabbitmq:4.3.6-managementde62d9901fb7
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
library/rabbitmq:4.3.4-managementeb5295d08332
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.16
1
library/redis:8.6.2009cc37796fb
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u3
1
library/redis:8.8.0234c902a2db4
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
library/redis:8.10.1:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
library/redis:7.2-alpine29e8589c3f9b
openssl@3.3.7-r1
3.3.7-r2
1
library/redis:7.0.15352c1fdadc91
openssl@3.0.14-1~deb12u2
no fix listed
1
library/redis:8.4.03906b477e4b6
openssl@3.0.17-1~deb12u3
no fix listed
1
library/redis:8.8.1-trixie3eafabb4c93f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
library/redis:8.2.24521b581dbdd
openssl@3.0.17-1~deb12u3
no fix listed
1
library/redis:8.6.34d25e2fe601f
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u3
1
library/redis:8.2.15fa2edb1e408
openssl@3.0.17-1~deb12u2
no fix listed
1
library/redis:6.2.20-alpine77697a75da9f
openssl@3.3.5-r0
3.3.7-r2
1
library/redis83edc2b8e9ff
openssl@3.0.17-1~deb12u2
no fix listed
1
library/redis:8.4a17e6c4fec82
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/redis:8.8.3b2ba68d56e7e
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/redis:8.0.2b43d2dcbbdb1
openssl@3.0.16-1~deb12u1
no fix listed
1
library/redis:7.4.1bb142a9c18ac
openssl@3.0.15-1~deb12u1
no fix listed
1
library/redis:8.0.3be0a135f1955
openssl@3.0.17-1~deb12u2
no fix listed
1
library/redis:6.2d2ad7b21cafa
openssl@3.0.20-1~deb12u2
no fix listed
1
library/redis:8.2.3d31852005202
openssl@3.0.17-1~deb12u3
no fix listed
1
library/redmine:6.1.204ac44a2595b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
library/sonarqube:10.7.0-community0842dcd4c8f8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.30
1
library/sonarqube:10.0.0-communityef9723cf4fe4
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.30
1
library/telegraf:1.27507a3eecf809
openssl@3.0.11-1~deb12u2
no fix listed
1
library/tomcat:11.0.26-jdk17-temurin-noble333c23b95c94
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
library/traefik:3.3.5104204dadedf
openssl@3.3.3-r0
3.3.7-r2
1
library/ubuntu:22.04b8b6ee6aa931
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30
1
library/varnish:7.5.04d0bb287d87b
openssl@3.0.15-1~deb12u1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
openssl@3.0.11-1~deb12u2
no fix listed
1
library/wordpress:7.1.2-apache8ae73d594a15
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u3
1
library/wordpress:7.1.2-apachebb209c8ab111
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
library/wordpress:php8.1-apachef73396626d2f
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u3
1
library/xwiki:lts-postgres-tomcat9b8142bce157
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
library/zookeeper:3.8-temurin55d1e5b2e601
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.30
1
library/zookeeper:3.9.4dfa9ba46d14b
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.30
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.