StackRadar

CVE-2026-3731

High

Advisory

Published 8 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
555
of 17,787 indexed, latest versions
Container images
472
deployed by those charts
Fix available
2 of 2
affected packages

Security update for libssh

Carried by container images the latest versions of 555 of 17,787 indexed charts deploy, on 472 images.

Affected packageAffected versionsFixed inImages
libsshdeb0.6.3-4.3, 0.6.3-4.3ubuntu0.2, 0.8.0~20170825.94fa1e38-1ubuntu0.2, 0.8.0~20170825.94fa1e38-1ubuntu0.5+22 more0.6.3-4.3ubuntu0.6+esm5, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm7, 0.9.3-2ubuntu2.5+esm4, 0.9.6-2ubuntu0.22.04.7+4 more469
libsshrpm0.9.8-150600.11.3.10.9.8-150600.11.12.13
OSV records
DEBIAN-CVE-2026-3731UBUNTU-CVE-2026-3731SUSE-SU-2026:1310-1
Also known as
USN-8093-1, USN-8093-2

Charts affected

555 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
libssh@0.9.3-2ubuntu2.5
0.9.3-2ubuntu2.5+esm4

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4

Open the chart page →

15,230
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.7

Open the chart page →

9,248
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libssh@0.9.3-2ubuntu2.5
0.9.3-2ubuntu2.5+esm4

Open the chart page →

6,285
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-3731.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7

Open the chart page →

14,100

Container images carrying it

472 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
wazuh/wazuh-manager:4.4.121994f40e0da
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
wistefan/mvf:lateste0887302b2d8
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
wolveix/satisfactory-server:v1.9.1199be1064b18
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
xeotek/kadeck:6.3.439a3b37a17c5
libssh@0.9.6-2ubuntu0.22.04.4
0.9.6-2ubuntu0.22.04.7
1
xeotek/kadeck:4.2.94c6b04d9ce55
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.7
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.5+esm4
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.5+esm4
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
libssh@0.9.6-2ubuntu0.22.04.3
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
libssh@0.10.6-2ubuntu0.3
0.10.6-2ubuntu0.4
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
libssh@0.10.6-0+deb12u2
no fix listed
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
ghcr.io/dask/dask:2024.1.0080150de7d86
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
libssh@0.9.6-2ubuntu0.22.04.2
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/formancehq/membership:v1.11.024a0113d5fb0
libssh@0.9.6-2ubuntu0.22.04.4
0.9.6-2ubuntu0.22.04.7
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
libssh@0.10.6-2ubuntu0.2
0.10.6-2ubuntu0.4
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/jespernohr/dayz-dedicated-server:0.1.1ec01d3ac7887
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
libssh@0.10.6-2build2
0.10.6-2ubuntu0.4
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.5+esm4
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.5+esm4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.