StackRadar

CVE-2026-35414

High

Advisory

Published 2 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
260
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 260 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+45 more1:7.2p2-4ubuntu2.10+esm9, 1:8.9p1-3ubuntu0.15, 1:9.2p1-2+deb12u10, 1:9.6p1-3ubuntu13.16+1 more252
OSV records
DEBIAN-CVE-2026-35414UBUNTU-CVE-2026-35414
Also known as
USN-8222-1, USN-8577-1

Charts affected

260 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15

Open the chart page →

20,270
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16

Open the chart page →

4,305
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15

Open the chart page →

14,100

Container images carrying it

252 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
bitnamilegacy/git:latest4b08d0c5af8d
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
bnjbvr/kresus:0.22.137e216b182c8
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
calltelemetry/web:0.8.1-rc7205d13269e350
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
castopod/castopod:1.12.101fd37280cbb2
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
openssh@1:8.9p1-3ubuntu0.15
no fix listed
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
openssh@1:6.6p1-2ubuntu2.13
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
openssh@1:8.2p1-4ubuntu0.1
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
openssh@1:8.9p1-3ubuntu0.11
1:8.9p1-3ubuntu0.15
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
openssh@1:10.0p1-7+deb13u1
1:10.0p1-7+deb13u3
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
countly/countly-server:25.05.4e3c238248f99
openssh@1:8.2p1-4ubuntu0.4
no fix listed
1
cribl/cribl:3.0.2762747cb6796
openssh@1:7.6p1-4ubuntu0.3
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
openssh@1:8.9p1-3ubuntu0.13
1:8.9p1-3ubuntu0.15
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
openssh@1:8.2p1-4ubuntu0.13
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
esphome/esphome:2024.3.09ab8cc88b28c
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
esphome/esphome:2024.12.2b2c6322700ac
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
esphome/esphome:2025.3.0def8b6e4f517
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm9
1
falcosecurity/event-generator:latest932956d86c99
openssh@1:9.2p1-2+deb12u9
1:9.2p1-2+deb12u10
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
openssh@1:8.2p1-4ubuntu0.13
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
gethue/hue:4.11.011b649636e68
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
openssh@1:7.6p1-4ubuntu0.3
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
openssh@1:8.9p1-3ubuntu0.13
1:8.9p1-3ubuntu0.15
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
haugene/transmission-openvpn:4.0059216cfae4b
openssh@1:8.2p1-4ubuntu0.3
no fix listed
1
haveagitgat/tdarr:2.00.181256348872ce
openssh@1:8.2p1-4ubuntu0.4
no fix listed
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
openssh@1:8.2p1-4ubuntu0.11
no fix listed
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
hmediade/printserver-init:latest7f005eb6c718
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.15
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm9
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm9
1
ibmcom/microclimate-theia:lateste17bdccc5030
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm9
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
inseefrlab/shelly:cloudshell31f04ca7436b
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15
1
instill/artifact-backend:b28766ac4a393e601ed
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
instill/model-backend:611f0f2e980125e5ba5
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
itzg/minecraft-server:2026.9.04e29d14082d9
openssh@1:9.6p1-3ubuntu13.18
no fix listed
1
itzg/minecraft-server:latest8672e335dbef
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.