StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,960
of 17,813 indexed, latest versions
Container images
2,180
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,960 of 17,813 indexed charts deploy, on 2,180 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,539
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0636
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,960 by stars
ChartLatestAffected imagesRadar Score
dingtalk-botxxl-job-adminVerified publisher0.1.21 of 2See more

dingtalk-bot xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

3,185
kminionxxl-job-adminVerified publisher0.13.01 of 1See more

kminion xxl-job-admin 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
redpandadata/kminion:v2.3.256da99e8d0d3
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

668
nightingalexxl-job-adminVerified publisher0.2.113 of 6See more

nightingale xxl-job-admin 0.2.11

3 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.11
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
no fix listed
library/redis:6.2d2ad7b21cafa
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,738
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

3,196
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

1,338
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,718
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,697
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,573
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,191
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

7,966

Container images carrying it

2,180 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/zinclabs/openobserve:v0.8.127f8de509169
openssl@3.0.11-1~deb12u2
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.25
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
openssl@3.5.6-r0
3.5.7-r0
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.25
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
quay.io/cilium/hubble-ui:v0.13.3661d5de70501
openssl@3.5.2-r0
3.5.7-r0
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
openssl@3.0.15-1~deb12u1
no fix listed
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
openssl@3.0.17-1~deb12u2
no fix listed
1
quay.io/cortexproject/cortex:v1.21.18577eb292a01
openssl@3.5.6-r0
3.5.7-r0
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
openssl@3.5.4-r0
3.5.7-r0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
openssl@3.5.4-r0
3.5.7-r0
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25
1
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
openssl@3.5.6-r0
3.5.7-r0
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25
1
quay.io/heubeck/examiner:1.14.61154472ff8c4
openssl@3.0.17-1~deb12u3
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
openssl@3.0.20-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
openssl@3.0.19-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
openssl@3.0.19-1~deb12u2
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
openssl@3.0.20-1~deb12u2
no fix listed
1
quay.io/kannika/kannika-console:0.18.0cc024a8ee909
openssl@3.0.20-1~deb12u2
no fix listed
1
quay.io/kiwigrid/k8s-sidecar:2.7.15bc0c5634d4a
openssl@3.5.5-r0
3.5.7-r0
1
quay.io/kiwigrid/k8s-sidecar:2.7.3694950d736c8
openssl@3.5.6-r0
3.5.7-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
openssl@3.5.1-r0
3.5.7-r0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
openssl@3.5.5-r0
3.5.7-r0
1
quay.io/kubevirt/aaq-operator:v1.7.0d28a2daa5b15
openssl@3.5.1-r0
3.5.7-r0
1
quay.io/kubevirt/virt-operator:v1.7.037d2ef21e3e5
openssl@3.0.16-1~deb12u1
no fix listed
1
quay.io/kubevirt/virt-operator:v1.8.465d23c9ad917
openssl@3.0.18-1~deb12u2
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
openssl@3.0.16-1~deb12u1
no fix listed
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
openssl@3.5.4-r0
3.5.7-r0
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2
1
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.3-r0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.