StackRadar

CVE-2026-35189

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,945
of 17,985 indexed, latest versions
Container images
2,976
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,945 of 17,985 indexed charts deploy, on 2,976 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,680
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2296
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-35189DEBIAN-CVE-2026-35189UBUNTU-CVE-2026-35189ECHO-312d-f531-8c85
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 4 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,945 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,976 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
sslhep/servicex_code_gen_raw_uproot:v1.8.61494a81a474b
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
sslhep/servicex_code_gen_topcp:v1.8.6f7faf8c6c3e4
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
sslhep/servicex-did-finder-atlasopenmagic:v1.8.6bd738c952e72
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
sslhep/servicex-did-finder-cernopendata:v1.8.623a80e40ab18
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
sslhep/servicex-did-finder-xrootd:v1.8.69a9fb17458f1
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
stackstorm/st2actionrunner:3.888235ba70cad
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2api:3.86f56d239d280
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2auth:3.833ecfda16608
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2notifier:3.8f190a6212195
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2rulesengine:3.8259503496ff9
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2scheduler:3.8b1de2055c362
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2stream:3.81c8904a3bf67
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2timersengine:3.81bf35bfaf00c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2web:3.809989a26c8b7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stackstorm/st2workflowengine:3.819fdfffdbba8
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
stalwartlabs/stalwart:v0.16.1425001929f36a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u3
1
stashapp/stash:latest24dbd7607174
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm6
1
stashapp/stash-box:latesta534c8afdf39
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
statcan/ckan:2.93921305425b8
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm6
1
steamcmd/steamcmd:latest79cd766328de
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
strangebee/thehive:5.8.0-1a7f7b05fba24
openssl@3.0.20-1~deb12u2
no fix listed
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm6
1
streamnative/function-mesh:v0.29.04176923db03c
openssl@3.3.7-r0
3.3.7-r2
1
structurizr/onpremises:2025.11.094b5ffb5119c8
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
substratusai/verba:v0.4.0-baseURL261695be635eb
openssl@3.0.11-1~deb12u2
no fix listed
1
supabase/edge-runtime:v1.74.02781daf92394
openssl@3.0.19-1~deb12u2
no fix listed
1
supabase/edge-runtime:v1.59.0eff9c554d649
openssl@3.0.14-1~deb12u2
no fix listed
1
supabase/logflare:latesta82f96c8845c
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
supabase/postgres-meta:v0.96.6a84cc713585e
openssl@3.0.19-1~deb12u2
no fix listed
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
openssl@3.0.14-1~deb12u2
no fix listed
1
supabase/realtime:latest7a6d995635f7
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
supabase/realtime:v2.102.3aa1c92c0cf32
openssl@3.0.20-1~deb12u1
no fix listed
1
supabase/realtime:v2.33.8d207e6e23ad3
openssl@3.0.14-1~deb12u2
no fix listed
1
supabase/studio:20241021-9f9b08326d8070c55e9
openssl@3.0.14-1~deb12u2
no fix listed
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
openssl@3.0.20-1~deb12u2
no fix listed
1
supabase/studio:latestfdb56cfa1705
openssl@3.0.20-1~deb12u2
no fix listed
1
superseriousbusiness/gotosocial:0.22.10078ca451dda
openssl@3.3.7-r0
3.3.7-r2
1
supporttools/website:v132603fdbc9e708e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.16
1
svcosti/cidrapp:latest8428d87bc5d0
openssl@3.3.3-r0
3.3.7-r2
1
svix/diom-operator:0.3.085dba8f1caa8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm6
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.30
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
openssl@3.0.11-1~deb12u2
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm6
1
swimmwatch/cloakbrowser-mcp:1.14.1f6986203a121
openssl@3.0.22-1~deb12u1
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.30
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.