StackRadar

CVE-2026-35191

Low

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
929
of 17,957 indexed, latest versions
Container images
672
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 929 of 17,957 indexed charts deploy, on 672 images.

Affected packageAffected versionsFixed inImages
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+15 more3.5.5-1ubuntu3.6667
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
OSV records
UBUNTU-CVE-2026-35191DEBIAN-CVE-2026-35191
Also known as
USN-8847-1
Trending
Rank 41 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

929 by stars
ChartLatestAffected imagesRadar Score
yelbfairwinds-incubator0.1.11 of 5See more

yelb fairwinds-incubator 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

5,115
jenkinsfatihtepe-jenkins1.0.01 of 1See more

jenkins fatihtepe-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

2,766
fauxgpufauxgpuVerified publisher0.2.42 of 4See more

fauxgpu fauxgpu 0.2.4

2 of the 4 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/devops-dojo7/fauxgpu/api:0.2.428f706597c2f
openssl@3.5.7-1~deb13u2
no fix listed
ghcr.io/devops-dojo7/fauxgpu/trainer:0.2.47a304b60c95e
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

3,231
quickstartfeatureformVerified publisher0.1.12 of 3See more

quickstart featureform 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

3,053
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

7,754
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
openssl@3.5.5-1~deb13u1
no fix listed

Open the chart page →

5,627
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
openssl@3.5.5-1~deb13u1
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
openssl@3.5.5-1~deb13u1
no fix listed

Open the chart page →

11,425
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
openssl@3.5.5-1~deb13u1
no fix listed

Open the chart page →

5,406
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

5,740
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

6,076
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

5,740
fluent-bit-aggregatorfluent-bit-aggregatorOfficialVerified publisher1.1.21 of 1See more

fluent-bit-aggregator fluent-bit-aggregator 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
fluent/fluent-bit:5.1.2d792375ca8e5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,045
fluent-bit-collectorfluent-bit-collectorOfficialVerified publisher1.1.21 of 1See more

fluent-bit-collector fluent-bit-collector 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
fluent/fluent-bit:5.1.2d792375ca8e5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,045
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

1,955
fluxer-helmfluxer-helm0.3.02 of 18See more

fluxer-helm fluxer-helm 0.3.0

2 of the 18 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/fluxerapp/fluxer-gateway:2026.818.14094351d6f973843f
openssl@3.5.6-1~deb13u2
no fix listed
ghcr.io/fluxerapp/fluxer-media-proxy:2026.820.164955ced7544e6b3f
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

29,747
fr24feederfnzv0.1.21 of 1See more

fr24feeder fnzv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest3e0fbd0274eb
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

2,025
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
openssl@3.5.5-1~deb13u2
no fix listed

Open the chart page →

2,618
forgejoforgejo-captnbp-helm1.2.61 of 2See more

forgejo forgejo-captnbp-helm 1.2.6

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

2,045
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latestf6509fcf917a
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

3,479
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
no fix listed

Open the chart page →

6,696
garge-appgargeVerified publisher0.1.531 of 1See more

garge-app garge 0.1.53

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.22.0c4b8f096df6b
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

788
factoriogeek-cookbookVerified publisher1.2.21 of 2See more

factorio geek-cookbook 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
factoriotools/factorio:stable4ec5fea2e06b
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,533
sdtdgeek-cookbookVerified publisher0.3.21 of 1See more

sdtd geek-cookbook 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/reitermarkus/7d2d:main39953b387b61
openssl@3.5.4-1~deb13u2
no fix listed

Open the chart page →

2,732
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
openssl@3.5.1-1
no fix listed

Open the chart page →

9,690
cloudflare-tunnelgeneral-helm-chartsVerified publisher0.2.01 of 1See more

cloudflare-tunnel general-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latestb269e8abd07a
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

452
redisgengxiankun-charts0.2.01 of 1See more

redis gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

692
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latestb269e8abd07a
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

9,268
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-notifier:v1.0.3d1b0ce10b513
openssl@3.5.6-1~deb13u1
no fix listed

Open the chart page →

12,534
glauthglauthVerified publisher0.3.171 of 2See more

glauth glauth 0.3.17

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
nouchka/sqlite3:latestce0d90cbe832
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

2,893
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/mariadb:latestd4fdec0510ad
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
library/phpmyadmin:latest9e915766488a
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

12,059
goofy-chartgoofy-chart0.1.01 of 1See more

goofy-chart goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,390
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

22,464
openclawgpg-dev1.5.361 of 2See more

openclaw gpg-dev 1.5.36

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
openssl@3.5.5-1~deb13u2
no fix listed

Open the chart page →

1,868
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

16,107
video-analytics-demo-l4tgpu-operator0.1.31 of 3See more

video-analytics-demo-l4t gpu-operator 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
gtmgtmVerified publisher1.0.21 of 1See more

gtm gtm 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

632
gwangju_2-3gwangju2-30.1.01 of 5See more

gwangju_2-3 gwangju2-3 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
fluent/fluent-bit:latestd792375ca8e5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

7,076
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest6f2ea2aae300
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,433
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

1,911
hatchet-hahatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-ha hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

8,172
hatchet-stackhatchetOfficialVerified publisher0.19.01 of 8See more

hatchet-stack hatchet 0.19.0

1 of the 8 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

8,172
web-charthcpark-ktcloudlab0.1.01 of 1See more

web-chart hcpark-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
test-apphellnet0.1.11 of 1See more

test-app hellnet 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
my_web1helm-chart-by-piyush0.1.01 of 1See more

my_web1 helm-chart-by-piyush 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/httpd:latest454942557d44
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,370
jenkinshelm-chart-for-jenkinsVerified publisher1.0.01 of 1See more

jenkins helm-chart-for-jenkins 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

2,766
hello-world-charthelm-chart-test-hello-world0.1.01 of 1See more

hello-world-chart helm-chart-test-hello-world 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
mywebhelmchartwebapp0.0.51 of 1See more

myweb helmchartwebapp 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/httpd:latest454942557d44
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,370
my-apphelm-demo85640.2.71 of 2See more

my-app helm-demo8564 0.2.7

1 of the 2 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
affinehelmforgeVerified publisher1.0.11 of 3See more

affine helmforge 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-35191.

Container imageDigestPackageFixed in
library/redis:8.10.18a1efc5f4795
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

4,221

Container images carrying it

672 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
openssl@3.5.6-1~deb13u2
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
openssl@3.5.4-1~deb13u1
no fix listed
1
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
no fix listed
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
no fix listed
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
no fix listed
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
no fix listed
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
registry.gitlab.com/egos-tech/smtp:latestc5faeae6b5d0
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
openssl@3.5.6-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.25b0d50fcd5ea
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.14ed6de4d77e1
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab1a80159109e74
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
openssl@3.5.7-1~deb13u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.