StackRadar

CVE-2026-35414

High

Advisory

Published 2 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
260
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 260 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+45 more1:7.2p2-4ubuntu2.10+esm9, 1:8.9p1-3ubuntu0.15, 1:9.2p1-2+deb12u10, 1:9.6p1-3ubuntu13.16+1 more252
OSV records
DEBIAN-CVE-2026-35414UBUNTU-CVE-2026-35414
Also known as
USN-8222-1, USN-8577-1

Charts affected

260 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15

Open the chart page →

20,270
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16

Open the chart page →

4,305
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15

Open the chart page →

14,100

Container images carrying it

252 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jedi132000/nextapp:latestdc2a81e92f23
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
knspar/phronetis-operator:0.1.60c4f0543ee58
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
kong/httpbin:latesta6ac46531193
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
kusionstack/kusion:v0.14.0126c8f0b0976
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
laly9999/node-app:1dd0e503913e1
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
lancachenet/monolithic:latest37f28b362c93
openssh@1:9.6p1-3ubuntu13.18
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
openssh@1:9.6p1-3ubuntu13.16
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
langgenius/dify-plugin-daemon:main-localda995c129e2f
openssh@1:9.6p1-3ubuntu13.18
no fix listed
1
library/node:208f693eaa7e0a
openssh@1:9.2p1-2+deb12u9
1:9.2p1-2+deb12u10
1
library/python:3.8d41127070014
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
library/python:3.9da5aee29682d
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
openssh@1:7.6p1-4ubuntu0.3
no fix listed
1
linuxserver/code-server:4.10.1a5e43a05ae79
openssh@1:8.9p1-3ubuntu0.1
1:8.9p1-3ubuntu0.15
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssh@1:8.2p1-4ubuntu0.13
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
openssh@1:9.6p1-3ubuntu13.16
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.15
1
mindsdb/mindsdb:latest163011c09299
openssh@1:10.0p1-7+deb13u2
1:10.0p1-7+deb13u3
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
moreillon/api-proxy:latestd7d4a5463525
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
moreillon/food-manager:lateste8fd856e593d
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
moreillon/group-manager:latest3caa8f710ee0
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1
mshanley80/httpbin2022:latest5b189a70c0fb
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
muluder/prograncontrollermcord:0.1.843b597a93da7
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm9
1
omecproject/onos-progran:1.0.05715e5648aa0
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm9
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm9
1
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
openbas/caldera-server:5.1.0a277796d9724
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
opencsghq/kubectl:latestb6d87e1048c2
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
openproject/hocuspocus:release-338001b288dc1359dfb5
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
openssh@1:7.6p1-4ubuntu0.3
no fix listed
1
psorab/elibrary:latest53b68896c4ce
openssh@1:8.2p1-4ubuntu0.7
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
openssh@1:9.6p1-3ubuntu13.18
no fix listed
1
resouer/redis-slave:v2e2f198b49ba7
openssh@1:6.6p1-2ubuntu2
no fix listed
1
rundeck/rundeck:3.2.74d64fe56f767
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm9
1
rundeck/rundeck:3.0.16b13e8059ad72
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm9
1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
openssh@1:8.9p1-3ubuntu0.11
1:8.9p1-3ubuntu0.15
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.