StackRadar

CVE-2026-35189

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,956
of 17,985 indexed, latest versions
Container images
2,991
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,956 of 17,985 indexed charts deploy, on 2,991 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,694
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2297
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-35189DEBIAN-CVE-2026-35189ECHO-312d-f531-8c85UBUNTU-CVE-2026-35189
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 5 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,956 by stars
ChartLatestAffected imagesRadar Score
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm11
voltha/voltha-onos:5.1.8e038acb950d3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

45,109
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

11,911
cron-connectoropenfaas0.6.161 of 1See more

cron-connector openfaas 0.6.16

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaas/cron-connector:0.7.0982498e8a41e
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,246
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,604
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,413
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

1,273
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latest42acb460c63b
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

1,867
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

5,809
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,751
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.30

Open the chart page →

4,472
llm-stackopenproject-helm-chartsVerified publisher2.0.02 of 2See more

llm-stack openproject-helm-charts 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.16
library/python:3.12-slimf77ac9e44ae9
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,119
fineractopenshift0.1.12 of 4See more

fineract openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/mariadb:11.470cc072b29b4
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

8,931
kubedb-certifiedopenshift2026.7.105 of 8See more

kubedb-certified openshift 2026.7.10

5 of the 8 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-provisioner:v0.66.0e7041c3b41e7
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,863
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
mattermost/mattermost-team-edition:10.11.2b8bd1246cb3a
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

5,023
voyager-gatewayopenshift2026.1.151 of 2See more

voyager-gateway openshift 2026.1.15

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
no fix listed

Open the chart page →

3,272
sohaopensohaVerified publisher0.1.101 of 2See more

soha opensoha 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,292
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

81,964
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest6850ed976e7e
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
ghcr.io/open-webui/terminals-operator:latest5e1ceb6b3b26
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,280
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
openssl@1.1.1-1ubuntu2.1~18.04.6
openssl1.0@1.0.2n-1ubuntu5.4
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7

Open the chart page →

107,385
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

2,360
kubernetes-syncopslevelVerified publisher0.8.01 of 1See more

kubernetes-sync opslevel 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

2,209
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
openssl@1.0.1f-1ubuntu2.25
1.0.1f-1ubuntu2.27+esm17

Open the chart page →

26,967
hiveopstty0.1.92 of 4See more

hive opstty 0.1.9

2 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.7-r2
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,139
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

1,206
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

12,648
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.028 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

28 of the 40 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
openssl@3.0.16-1~deb12u1
no fix listed
chromadb/chroma:1.5.7fc8dc8e11fb2
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u3
library/mariadb:11.3.2e101f9db3191
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.30
library/postgres:17.2-alpine7e5df973a748
openssl@3.3.2-r4
3.3.7-r2
library/redis:7.4.2-alpine02419de7eddf
openssl@3.3.3-r0
3.3.7-r2
yetiplatform/bloomcheck:dev85683ddfccbb
openssl@3.3.3-r0
3.3.7-r2
yetiplatform/yeti:2.9.09bcbe2650a14
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
yetiplatform/yeti-frontend:2.9.0873ef15d267b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssl@3.0.13-1~deb12u1
no fix listed
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
openssl@3.0.18-1~deb12u2
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16

Open the chart page →

235,387
yetiosdfir-infrastructureVerified publisher1.0.52 of 4See more

yeti osdfir-infrastructure 1.0.5

2 of the 4 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
yetiplatform/yeti-frontend:latest709064278c7e
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

8,018
fluent-bitot-container-kit0.0.31 of 2See more

fluent-bit ot-container-kit 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,107
loki-standaloneot-container-kit1.0.22 of 5See more

loki-standalone ot-container-kit 1.0.2

2 of the 5 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

4,489
vm-standaloneot-container-kit0.0.42 of 6See more

vm-standalone ot-container-kit 0.0.4

2 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

4,554
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
otsotsVerified publisher1.9.01 of 2See more

ots ots 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/redis:8.10.2d5ac52db24d4
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

773
akash-hostname-operatorovrclk-211.5.11 of 1See more

akash-hostname-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
akash-inventory-operatorovrclk-211.5.11 of 1See more

akash-inventory-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
akash-ip-operatorovrclk-211.5.11 of 1See more

akash-ip-operator ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
console-apiovrclk-20.1.11 of 1See more

console-api ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/console-api:2.64.0ba359097329d
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

4,320
console-webovrclk-20.1.11 of 1See more

console-web ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

3,079
providerovrclk-211.5.11 of 1See more

provider ovrclk-2 11.5.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider:0.6.88c780ae8d1bb
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16

Open the chart page →

4,013
provider-consoleovrclk-20.1.01 of 1See more

provider-console ovrclk-2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
openssl@3.3.2-r4
3.3.7-r2

Open the chart page →

2,577
provider-proxyovrclk-20.1.11 of 1See more

provider-proxy ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider-proxy:1.4.353f533d7c6f8
openssl@3.3.3-r0
3.3.7-r2

Open the chart page →

3,231
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

4,339
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

3,896
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

2,588
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

4,547
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

13,132
ungatep2p-avs0.1.03 of 3See more

ungate p2p-avs 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
openssl@3.0.13-1~deb12u1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
openssl@3.0.13-1~deb12u1
no fix listed
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30

Open the chart page →

29,562
p4p40.1.04 of 7See more

p4 p4 0.1.0

4 of the 7 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm11
library/mongo:5.0-focal5e15a3f014ed
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm6
library/rabbitmq:3.11-managementc3f70098e01d
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.30
mastercloudapps/planner:v1.2340a950b311b2
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.30

Open the chart page →

30,492
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-35189.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

23,214

Container images carrying it

2,991 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.7-r2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssl@3.0.9-1
no fix listed
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm11
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
registry.gitlab.com/dyff/dyff-api:0.57.912b6fc5c8fc5
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r2
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
openssl@3.0.20-1~deb12u1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.4001e589acf2e
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestc5faeae6b5d0
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
openssl@3.5.6-1~deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
openssl@3.0.20-1~deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.25b0d50fcd5ea
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.14ed6de4d77e1
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab1a80159109e74
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.24+esm6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
openssl@3.0.20-1~deb12u1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u3
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
no fix listed
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r2
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.