StackRadar

CVE-2026-3731

High

Advisory

Published 8 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
555
of 17,787 indexed, latest versions
Container images
472
deployed by those charts
Fix available
2 of 2
affected packages

Security update for libssh

Carried by container images the latest versions of 555 of 17,787 indexed charts deploy, on 472 images.

Affected packageAffected versionsFixed inImages
libsshdeb0.6.3-4.3, 0.6.3-4.3ubuntu0.2, 0.8.0~20170825.94fa1e38-1ubuntu0.2, 0.8.0~20170825.94fa1e38-1ubuntu0.5+22 more0.6.3-4.3ubuntu0.6+esm5, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm7, 0.9.3-2ubuntu2.5+esm4, 0.9.6-2ubuntu0.22.04.7+4 more469
libsshrpm0.9.8-150600.11.3.10.9.8-150600.11.12.13
OSV records
DEBIAN-CVE-2026-3731UBUNTU-CVE-2026-3731SUSE-SU-2026:1310-1
Also known as
USN-8093-1, USN-8093-2

Charts affected

555 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
libssh@0.9.3-2ubuntu2.5
0.9.3-2ubuntu2.5+esm4

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4

Open the chart page →

15,230
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.7

Open the chart page →

9,248
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libssh@0.9.3-2ubuntu2.5
0.9.3-2ubuntu2.5+esm4

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7

Open the chart page →

14,100

Container images carrying it

472 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
libssh@0.10.6-0+deb12u2
no fix listed
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.5+esm4
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
2
1dev/server:11.9.0cd5b12fe5471
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
5200710/hadoop:3.2.3-java8092d3088a5fb
libssh@0.9.3-2ubuntu2.4
0.9.3-2ubuntu2.5+esm4
1
adorsys/keycloak-config-cli:6.3.0-26.1.085be7a45a94c
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
adorsys/keycloak-config-cli:6.1.6-25.0.1eb49a2dcbbb8
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.5+esm4
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
libssh@0.9.6-2ubuntu0.22.04.4
0.9.6-2ubuntu0.22.04.7
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.5+esm4
1
aktosecurity/data-ingestion-service213aded7adc5
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
anguda/ant-media:2.5c435285fc241
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
apache/activemq-artemis:2.44.00305c26f19ed
libssh@0.10.6-2ubuntu0.1
0.10.6-2ubuntu0.4
1
apache/activemq-artemis:2.37.0bae523439ee3
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libssh@0.9.6-2ubuntu0.22.04.4
0.9.6-2ubuntu0.22.04.7
1
apache/hertzbeat:1.8.075d48a62748f
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
apache/iotdb:0.13.3-nodeafa47bf1692a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
apache/nifi-registry:1.27.063b8e3e40742
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.7
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
apachepulsar/pulsar:3.0.79c9947de139d
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
apachepulsar/pulsar:2.9.0d056c89b7131
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
apachepulsar/pulsar:2.8.2d538416d5afe
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
apache/ranger:2.7.076c176e8a0e4
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
apache/rocketmq:5.3.0434d8398f996
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
apache/rocketmq-exporter:0.0.2c8fb51195444
libssh@0.9.6-2ubuntu0.22.04.2
0.9.6-2ubuntu0.22.04.7
1
apache/skywalking-oap-server:9.2.0133d35d2c263
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
apache/skywalking-ui:9.2.0295f1dc87d98
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
apache/skywalking-ui:8.9.180530f0308a5
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
archivebox/archivebox:0.7.41a5a37331091
libssh@0.10.6-0+deb12u2
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
libssh@0.10.6-2ubuntu0.1
0.10.6-2ubuntu0.4
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.5+esm4
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
assistiot/location_processing:lateste9bae124095f
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
assistiot/open_api_backend:1.1.230812ba93555
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.7
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.5+esm4
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
atlassian/confluence-server:7.10.03b9222ab32ef
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
atlassian/jira-software:8.14.037bc46cbec1a
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
atlassian/jira-software:9.7.264a75aa4ec4e
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.5+esm4
1
castlemock/castlemock:latestb7f3f1527ba9
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
castopod/castopod:1.12.101fd37280cbb2
libssh@0.10.6-0+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.