StackRadar

CVE-2026-35414

High

Advisory

Published 2 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
260
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 260 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+45 more1:7.2p2-4ubuntu2.10+esm9, 1:8.9p1-3ubuntu0.15, 1:9.2p1-2+deb12u10, 1:9.6p1-3ubuntu13.16+1 more252
OSV records
DEBIAN-CVE-2026-35414UBUNTU-CVE-2026-35414
Also known as
USN-8222-1, USN-8577-1

Charts affected

260 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15

Open the chart page →

20,270
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16

Open the chart page →

4,305
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15

Open the chart page →

14,100

Container images carrying it

252 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/grycap/im:latest06a16d4f279f
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
ghcr.io/itzg/minecraft-server:latestc1a267d9ed6d
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
openssh@1:9.2p1-2+deb12u5
1:9.2p1-2+deb12u10
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
openssh@1:8.2p1-4ubuntu0.4
no fix listed
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
openssh@1:10.0p1-7+deb13u1
1:10.0p1-7+deb13u3
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssh@1:9.6p1-3ubuntu13.3
1:9.6p1-3ubuntu13.16
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
openssh@1:9.2p1-2+deb12u6
1:9.2p1-2+deb12u10
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssh@1:9.2p1-2+deb12u4
1:9.2p1-2+deb12u10
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.15
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.15
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.15
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.16
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssh@1:9.6p1-3ubuntu13.13
1:9.6p1-3ubuntu13.16
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssh@1:7.2p2-4ubuntu2.10
1:7.2p2-4ubuntu2.10+esm9
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.