StackRadar

CVE-2026-35189

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,956
of 17,985 indexed, latest versions
Container images
2,991
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,956 of 17,985 indexed charts deploy, on 2,991 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,694
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2297
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-35189DEBIAN-CVE-2026-35189ECHO-312d-f531-8c85UBUNTU-CVE-2026-35189
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 5 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,956 by stars
ChartLatestAffected imagesRadar Score
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm11
voltha/voltha-onos:5.1.8e038acb950d3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

45,109
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

11,911
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,246
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,604
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,413
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,273
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latest42acb460c63b
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

1,867
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

5,809
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,751
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.30

Open the chart page →

4,472
llm-stackopenproject-helm-chartsVerified publisher2.0.02 of 2See more

llm-stack openproject-helm-charts 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.16
library/python:3.12-slimf77ac9e44ae9
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,119
fineractopenshift0.1.12 of 4See more

fineract openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/mariadb:11.470cc072b29b4
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

8,931
kubedb-certifiedopenshift2026.7.105 of 8See more

kubedb-certified openshift 2026.7.10

5 of the 8 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,863
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

5,023
voyager-gatewayopenshift2026.1.151 of 2See more

voyager-gateway openshift 2026.1.15

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
no fix listed

Open the chart page →

3,272
sohaopensohaVerified publisher0.1.101 of 2See more

soha opensoha 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,292
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

81,964
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest6850ed976e7e
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,280
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7

Open the chart page →

107,385
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

2,360
kubernetes-syncopslevelVerified publisher0.8.01 of 1See more

kubernetes-sync opslevel 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

2,209
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
openssl@1.0.1f-1ubuntu2.25
1.0.1f-1ubuntu2.27+esm17

Open the chart page →

26,967
hiveopstty0.1.92 of 4See more

hive opstty 0.1.9

2 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.7-r2
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,139
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

1,206
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

12,648
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.028 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

28 of the 40 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
openssl@3.0.16-1~deb12u1
no fix listed
chromadb/chroma:1.5.7fc8dc8e11fb2
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u3
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
library/postgres:17.2-alpine7e5df973a748
openssl@3.3.2-r4
3.3.7-r2
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.7-r2
yetiplatform/bloomcheck:dev85683ddfccbb
openssl@3.3.3-r0
3.3.7-r2
yetiplatform/yeti:2.9.09bcbe2650a14
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
yetiplatform/yeti-frontend:2.9.0873ef15d267b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
no fix listed
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
openssl@3.0.18-1~deb12u2
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16

Open the chart page →

235,387
yetiosdfir-infrastructureVerified publisher1.0.52 of 4See more

yeti osdfir-infrastructure 1.0.5

2 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
yetiplatform/yeti-frontend:latest709064278c7e
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

8,018
fluent-bitot-container-kit0.0.31 of 2See more

fluent-bit ot-container-kit 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,107
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

4,489
vm-standaloneot-container-kit0.0.42 of 6See more

vm-standalone ot-container-kit 0.0.4

2 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

4,554
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
otsotsVerified publisher1.9.01 of 2See more

ots ots 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/redis:8.10.2d5ac52db24d4
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

773
akash-hostname-operatorovrclk-211.5.11 of 1See more

akash-hostname-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
akash-inventory-operatorovrclk-211.5.11 of 1See more

akash-inventory-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
akash-ip-operatorovrclk-211.5.11 of 1See more

akash-ip-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
console-apiovrclk-20.1.11 of 1See more

console-api ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/console-api:2.64.0ba359097329d
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

4,320
console-webovrclk-20.1.11 of 1See more

console-web ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

3,079
providerovrclk-211.5.11 of 1See more

provider ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
provider-consoleovrclk-20.1.01 of 1See more

provider-console ovrclk-2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

2,577
provider-proxyovrclk-20.1.11 of 1See more

provider-proxy ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider-proxy:1.4.353f533d7c6f8
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

3,231
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

4,339
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

3,896
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

2,588
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

4,547
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

13,132
ungatep2p-avs0.1.03 of 3See more

ungate p2p-avs 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
openssl@3.0.13-1~deb12u1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
openssl@3.0.13-1~deb12u1
no fix listed
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

29,562
p4p40.1.04 of 7See more

p4 p4 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm11
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm6
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.30
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.30

Open the chart page →

30,492
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

23,214

Container images carrying it

2,991 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/zinclabs/openobserve:v0.8.127f8de509169
openssl@3.0.11-1~deb12u2
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.30
1
quay.io/argoproj/argocd:v2.10.783c86003b781
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.30
1
quay.io/argoprojlabs/gitops-promoter:v0.42.0105b74aaf5e9
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.30
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.16
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.16
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
openssl@3.0.15-1~deb12u1
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
openssl@3.0.17-1~deb12u2
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.30
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm11
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.30
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.30
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
quay.io/groundcover/tools:20260929e8a79ea4cf39
openssl@3.5.7-1~deb13u2+e1
3.5.7-1~deb13u3
1
quay.io/heubeck/examiner:1.14.61154472ff8c4
openssl@3.0.17-1~deb12u3
no fix listed
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
quay.io/jupyterhub/configurable-http-proxy:5.1.0eb10d5bf045c
openssl@3.3.4-r0
3.3.7-r2
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
openssl@3.0.20-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
openssl@3.0.19-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
openssl@3.0.19-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
openssl@3.0.20-1~deb12u2
no fix listed
1
quay.io/kannika/kannika-console:0.19.09f5d1079572d
openssl@3.0.20-1~deb12u2
no fix listed
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
openssl@3.3.3-r0
3.3.7-r2
1
quay.io/kubevirt/virt-operator:v1.7.037d2ef21e3e5
openssl@3.0.16-1~deb12u1
no fix listed
1
quay.io/kubevirt/virt-operator:v1.8.465d23c9ad917
openssl@3.0.18-1~deb12u2
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u3
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
openssl@3.0.16-1~deb12u1
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
openssl@1.0.2g-1ubuntu4.17
1.0.2g-1ubuntu4.20+esm19
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
openssl@3.3.7-r0
3.3.7-r2
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.16
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm19
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u3
1
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r2
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.