StackRadar

CVE-2026-35414

High

Advisory

Published 2 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
260
of 17,781 indexed, latest versions
Container images
252
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 260 of 17,781 indexed charts deploy, on 252 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+45 more1:7.2p2-4ubuntu2.10+esm9, 1:8.9p1-3ubuntu0.15, 1:9.2p1-2+deb12u10, 1:9.6p1-3ubuntu13.16+1 more252
OSV records
DEBIAN-CVE-2026-35414UBUNTU-CVE-2026-35414
Also known as
USN-8222-1, USN-8577-1

Charts affected

260 by stars
ChartLatestAffected imagesRadar Score
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

28,858
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.15

Open the chart page →

20,270
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16

Open the chart page →

4,305
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-35414.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.15

Open the chart page →

14,100

Container images carrying it

252 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm9
11
oomk8s/readiness-check:2.0.07daa08b81954
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm9
6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm9
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssh@1:7.2p2-4ubuntu2.8
1:7.2p2-4ubuntu2.10+esm9
4
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
openssh@1:8.9p1-3ubuntu0.16
no fix listed
4
quay.io/devtron/ai-agent:0.0.16545dac92173
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssh@1:8.9p1-3ubuntu0.1
1:8.9p1-3ubuntu0.15
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
openssh@1:9.6p1-3ubuntu13.18
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssh@1:9.2p1-2+deb12u7
1:9.2p1-2+deb12u10
3
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
2
cribl/cribl:4.19.2044f9a5fac9a
openssh@1:9.6p1-3ubuntu13.18
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
2
homebridge/homebridge:latest77c685a40911
openssh@1:9.6p1-3ubuntu13.18
no fix listed
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
openssh@1:10.0p1-7+deb13u1
1:10.0p1-7+deb13u3
2
library/python:3.7eedf63967cdb
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
openssh@1:8.2p1-4ubuntu0.1
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u10
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
openssh@1:7.2p2-4ubuntu2.7
1:7.2p2-4ubuntu2.10+esm9
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
openssh@1:8.2p1-4ubuntu0.5
no fix listed
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.15
2
uffizzi/controller:latest0344805f267b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
2
wurstmeister/zookeeper:latest7a7fd44a7210
openssh@1:6.6p1-2ubuntu2
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
openssh@1:9.6p1-3ubuntu13.19
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.16
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.15
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssh@1:9.6p1-3ubuntu13.9
1:9.6p1-3ubuntu13.16
2
1dev/server:11.9.0cd5b12fe5471
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.16
1
aboogie/login_test_backend:new9c41a4483ac8
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
openssh@1:7.6p1-4ubuntu0.7
no fix listed
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
openssh@1:9.6p1-3ubuntu13.18
no fix listed
1
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
apache/airflow:2.8.4-python3.964e58748b6b9
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
apache/airflow:2.8.1e5560ad0b86e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
apache/hertzbeat:1.8.075d48a62748f
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.16
1
apache/ranger:2.7.076c176e8a0e4
openssh@1:8.9p1-3ubuntu0.13
1:8.9p1-3ubuntu0.15
1
aristidetm/basic-notebook:3.6.5469dbc951224
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u10
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u10
1
arunvelsriram/utils:latest655ad18fd8d6
openssh@1:9.6p1-3ubuntu13.13
1:9.6p1-3ubuntu13.16
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
atlassian/bamboo:12.1.114af4bb6c8d46
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u10
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
openssh@1:10.0p1-7
1:10.0p1-7+deb13u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.