StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,914
of 17,790 indexed, latest versions
Container images
2,141
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,914 of 17,790 indexed charts deploy, on 2,141 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,503
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0633
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,914 by stars
ChartLatestAffected imagesRadar Score
cluster-importerappscodeVerified publisher2026.9.111 of 1See more

cluster-importer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,000
crd-managerappscodeVerified publisher2026.7.211 of 1See more

crd-manager appscode 2026.7.21

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

773
falco-ui-serverappscodeVerified publisher2026.1.151 of 2See more

falco-ui-server appscode 2026.1.15

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/falco-ui-server:v0.0.66ec488d89b56
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

2,873
fluxcd-managerappscodeVerified publisher2026.2.161 of 1See more

fluxcd-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.103475404bef5c
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,094
gcp-credential-managerappscodeVerified publisher2026.3.111 of 1See more

gcp-credential-manager appscode 2026.3.11

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/gcp-credential-manager:v0.1.0b58345fe8209
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,061
inbox-agentappscodeVerified publisher2026.6.21 of 2See more

inbox-agent appscode 2026.6.2

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-agent:v0.0.66b99ee9feece
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

2,115
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.25

Open the chart page →

4,002
inbox-server-distributedappscodeVerified publisher2025.12.253 of 4See more

inbox-server-distributed appscode 2025.12.25

3 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.25
library/rabbitmq:3.12.1-managementf020c06da226
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
ghcr.io/appscode/inbox-server:latest536358d7b17e
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.25

Open the chart page →

15,707
james-komposeappscodeVerified publisher0.1.03 of 4See more

james-kompose appscode 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.25
library/rabbitmq:3.12.1-managementf020c06da226
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25

Open the chart page →

17,110
kubedb-autoscalerappscodeVerified publisher0.51.01 of 1See more

kubedb-autoscaler appscode 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

502
kubedb-certifiedappscodeVerified publisher2026.7.106 of 8See more

kubedb-certified appscode 2026.7.10

6 of the 8 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/petset:v0.1.093fa0daf603c
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

4,048
kubedb-crd-managerappscodeVerified publisher0.21.01 of 1See more

kubedb-crd-manager appscode 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

486
kubedb-gitopsappscodeVerified publisher0.14.01 of 1See more

kubedb-gitops appscode 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-gitops:v0.14.0c743f8d7a199
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

450
kubedb-oneappscodeVerified publisher2023.12.281 of 10See more

kubedb-one appscode 2023.12.28

1 of the 10 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

15,016
kubedb-ops-managerappscodeVerified publisher0.53.01 of 1See more

kubedb-ops-manager appscode 0.53.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

555
kubedb-webhook-serverappscodeVerified publisher0.42.01 of 1See more

kubedb-webhook-server appscode 0.42.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

459
kubevaultappscodeVerified publisher2026.8.71 of 2See more

kubevault appscode 2026.8.7

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

789
kubevault-certifiedappscodeVerified publisher2026.2.271 of 1See more

kubevault-certified appscode 2026.2.27

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.24.00087cb49616f
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

1,112
kubevault-operatorappscodeVerified publisher0.25.01 of 1See more

kubevault-operator appscode 0.25.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

487
kubevault-webhook-serverappscodeVerified publisher0.25.01 of 2See more

kubevault-webhook-server appscode 0.25.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kubevault/vault-operator:v0.25.0c8e042b5cee8
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

789
license-proxyserverappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,106
license-proxyserver-managerappscodeVerified publisher2026.2.161 of 1See more

license-proxyserver-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.1.1e192ad567e0b
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,106
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,605
offline-license-serverappscodeVerified publisher2026.9.112 of 2See more

offline-license-server appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/maxmind-geoip:city-mmdb-latesta3236324c4e2
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,682
petsetappscodeVerified publisher2026.5.221 of 1See more

petset appscode 2026.5.22

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/petset:v0.1.093fa0daf603c
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

854
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,565
platform-apiappscodeVerified publisher2026.9.113 of 3See more

platform-api appscode 2026.9.11

3 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2
ghcr.io/appscode/maxmind-geoip:city-mmdb-latesta3236324c4e2
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

37,184
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25

Open the chart page →

3,310
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,330
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,088
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

2,224
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,076
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,221
voyager-gatewayappscodeVerified publisher2026.7.211 of 2See more

voyager-gateway appscode 2026.7.21

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,265
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
openssl@3.0.9-1
no fix listed

Open the chart page →

4,899
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

9,847
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
openssl@3.5.1-1
3.5.6-1~deb13u2

Open the chart page →

7,521
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

7,338
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0d041bbf2814f
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

4,819
arlas-aiasarlas-stackVerified publisher28.8.010 of 22See more

arlas-aias arlas-stack 28.8.0

10 of the 22 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
openssl@3.0.16-1~deb12u1
no fix listed
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
openssl@3.0.16-1~deb12u1
no fix listed
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

40,411
arlas-uisarlas-stackVerified publisher28.8.01 of 4See more

arlas-uis arlas-stack 28.8.0

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

2,987
assemblylineassemblylineVerified publisher7.4.194 of 12See more

assemblyline assemblyline 7.4.19

4 of the 12 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable19c914f21a41d7
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-rust:4.7.4.stable19c2f9619d9bcd
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-socketio:4.7.4.stable19caf40394bd17
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui:4.7.4.stable190426ed7884a2
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

12,092
dltkvassist-iot-data-integrity-verification0.2.01 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
no fix listed

Open the chart page →

77,821
dltflassist-iot-dlt-based-fl0.2.01 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
no fix listed

Open the chart page →

77,821
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

12,799
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25

Open the chart page →

10,101
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25

Open the chart page →

18,331
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssl@3.0.9-1
no fix listed

Open the chart page →

42,460
account-monitorastria0.0.11 of 1See more

account-monitor astria 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,870
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.25
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

31,807

Container images carrying it

2,141 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
omkara25/simple-microservice-app-user-service:v2d62cba548580
openssl@3.0.16-1~deb12u1
no fix listed
1
ondrejsika/counter:latestd95eaeee2172
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2
1
onyxdotapp/onyx-backend:latest473fdffe4e67
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2
1
opea/asr:1.025dd26d9cd09
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/chatqna:1.038c51b791efa
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/codegen:1.058f91683892d
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
openssl@3.0.11-1~deb12u2
no fix listed
1
opea/codetrans:1.0e2436483b73d
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
openssl@3.0.11-1~deb12u2
no fix listed
1
opea/docsum:1.03eaa91849512
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
openssl@3.0.11-1~deb12u2
no fix listed
1
opea/guardrails-tgi:1.0262c6048aab8
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/guardrails-tgi:latestf68bec6a1271
openssl@3.0.15-1~deb12u1
no fix listed
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/speecht5:1.0249afad3d268
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/tts:1.0257ae94709e9
openssl@3.0.14-1~deb12u2
no fix listed
1
opea/web-retriever-chroma:1.0fe08165d7770
openssl@3.0.14-1~deb12u2
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
openssl@3.0.15-1~deb12u1
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
openssl@3.0.17-1~deb12u2
no fix listed
1
opencsghq/csghub-portal:v2.4.0-ee93ad59164d87
openssl@3.0.20-1~deb12u2
no fix listed
1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
openssl@3.0.18-1~deb12u1
no fix listed
1
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
openssl@3.0.18-1~deb12u1
no fix listed
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
openssl@3.0.14-1~deb12u2
no fix listed
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
openssl@3.0.14-1~deb12u2
no fix listed
1
opencsghq/kubectl:latestb6d87e1048c2
openssl@3.0.17-1~deb12u3
no fix listed
1
opendatacube/explorer:latest120457ffcd69
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
opendatacube/wps:latest80df355a660b
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25
1
openebs/lvm-driver:1.10.141f73aba7f31
openssl@3.5.1-r0
3.5.7-r0
1
openmined/syft-backend:0.9.5b72f74a68b32
openssl@3.4.1-r0
3.6.3-r0
1
openmined/syft-frontend:0.9.5d11524a3854a
openssl@3.4.1-r0
3.6.3-r0
1
openproject/hocuspocus:release-338001b288dc1359dfb5
openssl@3.0.17-1~deb12u2
no fix listed
1
openresty/openresty:1.31.1.1-1-alpine-fatacd832254d9c
openssl@3.5.6-r0
3.5.7-r0
1
openvino/model_server:2025.2.11e7cd1d70cc1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.7-r0
1
outlinewiki/outline:0.82.0494dfb9249a6
openssl@3.0.15-1~deb12u1
no fix listed
1
owncloud/ocis:8.0.1b38fd8fdd58f
openssl@3.5.5-r0
3.5.7-r0
1
owncloud/server:10.16.274c53d341076
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25
1
owncloud/server:10.16.3b3f9efdcd7f7
openssl@3.0.2-0ubuntu1.25
no fix listed
1
pangeo/base-notebook:2024.01.155fbe688a4f80
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.25
1
penpotapp/backend:2.2.147853d9bb9dd
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
penpotapp/exporter:2.2.15c835ffd87ab
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
openssl@3.5.6-r0
3.5.7-r0
1
pgvector/pgvector:pg17cf134a767f47
openssl@3.0.20-1~deb12u2
no fix listed
1
phan2410/dummy-service:0.0.89c6ed6de26ca
openssl@3.0.15-1~deb12u1
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
openssl@3.0.15-1~deb12u1
no fix listed
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
photoprism/photoprism:220629-jammy2954334adbda
openssl@3.0.2-0ubuntu1.5
3.0.2-0ubuntu1.25
1
photoprism/photoprism:260601650c6ad5a651
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.