StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,941
of 17,828 indexed, latest versions
Container images
2,168
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,941 of 17,828 indexed charts deploy, on 2,168 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+52 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,531
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0632
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,941 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,168 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
library/redis:8.0.3be0a135f1955
openssl@3.0.17-1~deb12u2
no fix listed
1
library/redis:7.4c6eabf748fc7
openssl@3.0.20-1~deb12u2
no fix listed
1
library/redis:6.2d2ad7b21cafa
openssl@3.0.20-1~deb12u2
no fix listed
1
library/redis:8.2.3d31852005202
openssl@3.0.17-1~deb12u3
no fix listed
1
library/sonarqube:10.7.0-community0842dcd4c8f8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
library/sonarqube:10.0.0-communityef9723cf4fe4
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
1
library/teamspeak:3.13.74d3fa1c0db9a
openssl@3.5.6-r0
3.5.7-r0
1
library/telegraf:1.27507a3eecf809
openssl@3.0.11-1~deb12u2
no fix listed
1
library/traefik:v3.6.1334d5089d0b41
openssl@3.5.6-r0
3.5.7-r0
1
library/ubuntu:22.04b8b6ee6aa931
openssl@3.0.2-0ubuntu1.29
no fix listed
1
library/varnish:7.5.04d0bb287d87b
openssl@3.0.15-1~deb12u1
no fix listed
1
library/varnish:alpinea84e1d4adb58
openssl@3.5.5-r0
3.5.7-r0
1
library/wordpress:6.4.3-apache8ae66efb09a2
openssl@3.0.11-1~deb12u2
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2
1
library/wordpress:php8.1-apachef73396626d2f
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2
1
library/znc:1.10.1c731c6a9b8b6
openssl@3.5.6-r0
3.5.7-r0
1
library/zookeeper:3.8-temurin55d1e5b2e601
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
1
library/zookeeper:3.9.4dfa9ba46d14b
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.25
1
library/zookeeper:3.9.5f258365d4882
openssl@3.0.2-0ubuntu1.26
no fix listed
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
openssl@3.0.18-1~deb12u2
no fix listed
1
lifailon/openrouter-bot:latestea37e4b6b952
openssl@3.5.1-r0
3.5.7-r0
1
linkstackorg/linkstack:latest1c8b05399ee4
openssl@3.5.5-r0
3.5.7-r0
1
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
openssl@3.5.5-r0
3.5.7-r0
1
linuxserver/bookstack:26.05.202605282ebf97852661
openssl@3.5.6-r0
3.5.7-r0
1
linuxserver/calibre-web:0.6.24241009026e6f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
linuxserver/code-server:4.10.1a5e43a05ae79
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.25
1
linuxserver/foldingathome:7.6.219a997426d71e
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.11
1
linuxserver/jackett:0.24.20929bca08e2e6f1
openssl@3.5.6-r0
3.5.7-r0
1
linuxserver/jackett:0.24.2066f1f23e0c9845
openssl@3.5.6-r0
3.5.7-r0
1
linuxserver/overseerr:1.35.06108ed066d4a
openssl@3.5.5-r0
3.5.7-r0
1
linuxserver/prowlarr:2.4.0.5397-ls149a46d0ce0a823
openssl@3.5.6-r0
3.5.7-r0
1
lis314/project-zomboid-docker:latestaa2089c37920
openssl@3.0.15-1~deb12u1
no fix listed
1
lissy93/domain-locker:latestd3c95edc0a8b
openssl@3.5.6-r0
3.5.7-r0
1
lissy93/networking-toolbox:latest700862839553
openssl@3.5.5-r0
3.5.7-r0
1
listmonk/listmonk:v6.0.0bf3903d54a46
openssl@3.5.4-r0
3.5.7-r0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
openssl@3.6.1-r3
3.6.3-r0
1
litlyx/litlyx-consumer:latest02225e77d316
openssl@3.5.4-r0
3.5.7-r0
1
litlyx/litlyx-dashboard:lateste64ff2d52385
openssl@3.5.4-r0
3.5.7-r0
1
litlyx/litlyx-producer:latest10407f36613f
openssl@3.5.4-r0
3.5.7-r0
1
livekit/ingress:v1.2.21ab01641b366
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
1
livekit/livekit-server:v1.9.03602a85840d5
openssl@3.5.0-r0
3.5.7-r0
1
livekit/livekit-server:v1.12.0b1281e66e35e
openssl@3.5.6-r0
3.5.7-r0
1
lmacka/snappass:2.1.293f5c048b7d4
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2
1
localstack/localstack:3.19d278167f2b7
openssl@3.0.11-1~deb12u2
no fix listed
1
locustio/locust:2.24.151d866285170
openssl@3.0.11-1~deb12u2
no fix listed
1
loeken/home-assistant:2026.5.14ce6abc553b3
openssl@3.5.6-r0
3.5.7-r0
1
loeken/jellyfin:10.11.87efbc24e47b0
openssl@3.5.6-r0
3.5.7-r0
1
logiqai/flash:v3.10.265b996bc7bdc
openssl@3.0.14-1~deb12u2
no fix listed
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
openssl@3.0.18-1~deb12u2
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
openssl@3.0.17-1~deb12u3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.