StackRadar

CVE-2026-35414

High

Advisory

Published 2 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
260
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 260 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+45 more1:7.2p2-4ubuntu2.10+esm9, 1:8.9p1-3ubuntu0.15, 1:9.2p1-2+deb12u10, 1:9.6p1-3ubuntu13.16+1 more252
OSV records
DEBIAN-CVE-2026-35414UBUNTU-CVE-2026-35414
Also known as
USN-8222-1, USN-8577-1

Charts affected

260 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15

Open the chart page →

20,270
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16

Open the chart page →

4,305
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15

Open the chart page →

14,100

Container images carrying it

252 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
seafileltd/seafile-mc:9.0.106693911bcc40
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
openssh@1:8.2p1-4ubuntu0.7
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
seldonio/locust-core:0.81d0da98a2d76
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm9
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
stackstorm/st2actionrunner:3.888235ba70cad
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2api:3.86f56d239d280
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2auth:3.833ecfda16608
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2notifier:3.8f190a6212195
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2rulesengine:3.8259503496ff9
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2scheduler:3.8b1de2055c362
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2stream:3.81c8904a3bf67
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2timersengine:3.81bf35bfaf00c
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
stackstorm/st2workflowengine:3.819fdfffdbba8
openssh@1:8.2p1-4ubuntu0.9
no fix listed
1
statcan/ckan:2.93921305425b8
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
substratusai/verba:v0.4.0-baseURL261695be635eb
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
openssh@1:8.9p1-3ubuntu0.7
1:8.9p1-3ubuntu0.15
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
openssh@1:8.2p1-4ubuntu0.7
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
teknas09/bird-pod:latest12a1fa85c4aa
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
theradius/loggia:0.463ba348546ec
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
treskon/portrait-web-setup:DEV-latesta475d80e4ecf
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
vlebediantsev/notes-admin-front:latest007c6670ff48
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
vlebediantsev/notes-project-front:latest945675fd2636
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
voltha/voltha-cli:1.6.0c4e41e92f046
openssh@1:7.2p2-4ubuntu2.6
1:7.2p2-4ubuntu2.10+esm9
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
openssh@1:7.6p1-4ubuntu0.3
no fix listed
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
openssh@1:9.6p1-3ubuntu13.18
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.