StackRadar

CVE-2026-35189

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,961
of 17,985 indexed, latest versions
Container images
2,998
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,961 of 17,985 indexed charts deploy, on 2,998 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,700
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2298
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-35189DEBIAN-CVE-2026-35189UBUNTU-CVE-2026-35189ECHO-312d-f531-8c85
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 4 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,961 by stars
ChartLatestAffected imagesRadar Score
ceph-exporterygqygq2Verified publisher1.0.01 of 1See more

ceph-exporter ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
digitalocean/ceph_exporter:latest3ba058e9a48d
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

6,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,894
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

2,577
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,887
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,901
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

637
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,836
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,003
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,129
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

9,659
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
openssl@3.0.2-0ubuntu1.30
no fix listed

Open the chart page →

6,257

Container images carrying it

2,998 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
pozetroninc/keydb:v6.0.1653ae64f29da8
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11
1
praravind1801/helmimages:3.0.0f29d637b9ce1
openssl@3.0.11-1~deb12u2
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
openssl@3.0.13-1~deb12u1
no fix listed
1
prefecthq/prefect:3.8.7-python3.11b3cdfebebff0
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
prefecthq/prometheus-prefect-exporter:4.1.06e0e79cabdc2
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
pretix/standalone:2026.7.05df3b7aa852e
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
probely/farcaster-onprem-agent:v3741b34e8166f
openssl@3.0.20-1~deb12u2
no fix listed
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
openssl@3.5.1-1
3.5.7-1~deb13u3
1
project2team4/react:latest3ff031a08887
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm6
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.16
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
openssl@3.0.14-1~deb12u2
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
openssl@3.0.20-1~deb12u2
no fix listed
1
proxysql/proxysql:3.0.8947a7abad45b
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
proxysql/proxysql:2.7.3a4d6c35c2949
openssl@3.0.15-1~deb12u1
no fix listed
1
pschichtel/mindustry-server:v145.1b543e9c2d371
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.30
1
psorab/elibrary:latest53b68896c4ce
openssl@1.1.1f-1ubuntu2.18
1.1.1f-1ubuntu2.24+esm6
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm6
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
openssl@1.1.1-1ubuntu2.1~18.04.15
1.1.1-1ubuntu2.1~18.04.23+esm11
1
purestream711/nostalgiatv-server:0.10.15-20260930-0305b2f577c87b17
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed
1
qdrant/qdrant:v1.7.45f2a56b95266
openssl@3.0.11-1~deb12u2
no fix listed
1
qdrant/qdrant:v1.4.166ee661d5241
openssl@3.0.9-1
no fix listed
1
qjoly/kubernetes-coffee-image:simple9f0c5ce8b5d7
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
qonstrukt/php:8.4-v8-apache089af7925aa1
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
1
quickwit/quickwit:v0.8.1d29332bdadcc
openssl@3.0.11-1~deb12u2
no fix listed
1
qumine/minecraft-server:v0.1.15c0b650d51132
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.30
1
rabeh/apibootspring:1.0941007b6946e
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.30
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm19
1
razorbladex401/dayz:latest6a4d79248e7d
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
1
readysettech/sqp:latest588f3507280e
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.16
1
readysettech/sqp-duckdb:latest67a83203ce60
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.16
1
reallibrephotos/librephotos-proxy:1.0.398a13dabbadc
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
reaper99/recipya:v1.2.27f7ec3aeb88c
openssl@3.3.2-r4
3.3.7-r2
1
redash/redash:25.8.000d813437db5
openssl@3.0.17-1~deb12u1
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
openssl@3.0.18-1~deb12u2
no fix listed
1
redimp/otterwiki:2d87a26b98d1a
openssl@3.0.20-1~deb12u2
no fix listed
1
redis/redisinsight:3.2.055542a762210
openssl@3.3.6-r0
3.3.7-r2
1
redis/redis-stack-server:6.2.6-v251a58f32d412
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm6
1
redis/redis-stack-server:latest798ab84d9f26
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.30
1
redis/redis-stack-server:7.4.0-v0887cf87cc744
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.30
1
redpandadata/redpanda:latest9e83cfa99278
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
reportportal/service-auto-analyzer:5.15.5c449b93629a5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
resouer/redis-slave:v2e2f198b49ba7
openssl@1.0.1f-1ubuntu2.8
1.0.1f-1ubuntu2.27+esm17
1
resurfaceio/resurface:3.7.84d5cda2f64109
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.30
1
rezachalak/bzen-mongo:1.0.034f694325191
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm6
1
rhasspy/wyoming-openwakeword:2.1.052cb1168731a
openssl@3.0.17-1~deb12u3
no fix listed
1
rhasspy/wyoming-piper:2.3.169b7f797ae3a
openssl@3.0.20-1~deb12u2
no fix listed
1
rhasspy/wyoming-piper:2.5.27d39aafac409
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.