StackRadar

CVE-2026-35386

High

Advisory

Published 2 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
241
of 17,781 indexed, latest versions
Container images
235
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 241 of 17,781 indexed charts deploy, on 235 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+43 more1:8.9p1-3ubuntu0.15, 1:9.2p1-2+deb12u10, 1:9.6p1-3ubuntu13.16, 1:9.6p1-3ubuntu13.16+Fips1+1 more235
OSV records
DEBIAN-CVE-2026-35386UBUNTU-CVE-2026-35386
Also known as
USN-8222-1

Charts affected

241 by stars
ChartLatestAffected imagesRadar Score
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

16,620
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

10,209
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

23,007
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
openssh@1:8.2p1-4ubuntu0.5
no fix listed

Open the chart page →

9,196
slothsloth0.16.01 of 2See more

sloth sloth 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3

Open the chart page →

3,962
aafsmo-helm-chart6.0.01 of 14See more

aaf smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,769
aaismo-helm-chart6.0.01 of 14See more

aai smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,803
dgbuildersmo-helm-chart6.0.01 of 3See more

dgbuilder smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
no fix listed

Open the chart page →

28,470
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

24,776
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
no fix listed

Open the chart page →

29,220
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

24,776
msbsmo-helm-chart6.0.01 of 6See more

msb smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
no fix listed

Open the chart page →

27,477
pndasmo-helm-chart6.0.01 of 3See more

pnda smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
no fix listed

Open the chart page →

27,477
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
no fix listed

Open the chart page →

29,220
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
no fix listed

Open the chart page →

27,477
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
no fix listed

Open the chart page →

25,769
spacecapybara-chartspacecapy1.0.491 of 2See more

spacecapybara-chart spacecapy 1.0.49

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
sashafefler/spacecapybara_app:latestf96d7804c0ca
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,888
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

20,223
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10

Open the chart page →

6,779
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

13,390
convert-datasvtechVerified publisher0.13.21 of 3See more

convert-data svtech 0.13.2

1 of the 3 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
openssh@1:8.9p1-3ubuntu0.7
1:8.9p1-3ubuntu0.15

Open the chart page →

7,588
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.15

Open the chart page →

12,048
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.15

Open the chart page →

12,048
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
openssh@1:8.2p1-4ubuntu0.7
no fix listed

Open the chart page →

18,756
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15

Open the chart page →

20,270
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16

Open the chart page →

4,305
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35386.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15

Open the chart page →

14,100

Container images carrying it

235 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
openssh@1:10.0p1-7+deb13u1
1:10.0p1-7+deb13u3
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssh@1:9.6p1-3ubuntu13.3
1:9.6p1-3ubuntu13.16
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.15
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.15
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.15
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.16
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssh@1:9.6p1-3ubuntu13.13
1:9.6p1-3ubuntu13.16
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssh@1:7.2p2-4ubuntu2.10
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.