StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,919
of 17,797 indexed, latest versions
Container images
2,146
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,919 of 17,797 indexed charts deploy, on 2,146 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,508
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0633
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,919 by stars
ChartLatestAffected imagesRadar Score
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

3,300
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,184
evm-rollupastria4.1.02 of 2See more

evm-rollup astria 4.1.0

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.7-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

4,019
evm-stackastria5.0.32 of 2See more

evm-stack astria 5.0.3

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.7-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

4,019
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,717
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,572
hermesastria0.7.11 of 1See more

hermes astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

2,007
hyperlane-agentsastria0.1.41 of 2See more

hyperlane-agents astria 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25

Open the chart page →

2,547
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

6,344
sequencer-relayerastria2.0.01 of 1See more

sequencer-relayer astria 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,960
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

9,449
autopushautopushVerified publisher0.0.492 of 4See more

autopush autopush 0.0.49

2 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

3,016
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25

Open the chart page →

6,965
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

6,338
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
openssl@3.0.15-1~deb12u1
no fix listed
kuzwolka/aws9:news3e8880fbbb96
openssl@3.0.15-1~deb12u1
no fix listed
kuzwolka/aws9:blog4a7707410bf1
openssl@3.0.15-1~deb12u1
no fix listed
kuzwolka/aws9:shop84a9d9766345
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

18,508
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25

Open the chart page →

3,319
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25

Open the chart page →

5,909
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

2,761
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

6,338
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,724
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

4,071
qbittorrent-vpnbdclark-helm-chartsVerified publisher0.7.61 of 2See more

qbittorrent-vpn bdclark-helm-charts 0.7.6

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.41.11a5bf4b4820a
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,010
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,929
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

2,138
helm-samplebehnambm-helm-chart1.0.11 of 3See more

helm-sample behnambm-helm-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/redis:771da9275c5f3
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,757
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25

Open the chart page →

7,266
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11

Open the chart page →

5,138
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,343
sm-operatorbitwarden2.0.31 of 1See more

sm-operator bitwarden 2.0.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

533
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

10,234
bdbablackduck2026.6.31 of 9See more

bdba blackduck 2026.6.3

1 of the 9 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/postgres:15.18-bookworme8db9bd3e9e1
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,718
blackduck-alertblackduck8.4.03 of 4See more

blackduck-alert blackduck 8.4.0

3 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
openssl@3.5.6-r0
3.5.7-r0
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
openssl@3.5.6-r0
3.5.7-r0
blackducksoftware/blackduck-alert-rabbitmq:8.4.08f422b18d171
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

4,284
colosseumbook-k8sinfra-v21.0.184 of 5See more

colosseum book-k8sinfra-v2 1.0.18

4 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-agg:logbc25b152d88e
openssl@3.0.2-0ubuntu1.25
no fix listed
sysnet4admin/colosseum-cms:loge74b43c7f492
openssl@3.0.16-1~deb12u1
no fix listed
sysnet4admin/colosseum-prm:log5802bfcd7fed
openssl@3.0.16-1~deb12u1
no fix listed
sysnet4admin/colosseum-rwd:log74ded2d92f07
openssl@3.5.1-1+deb13u1
3.5.6-1~deb13u2

Open the chart page →

27,239
csi-driver-nfsbook-k8sinfra-v24.12.11 of 6See more

csi-driver-nfs book-k8sinfra-v2 4.12.1

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

6,269
jaegerbook-k8sinfra-v23.4.01 of 5See more

jaeger book-k8sinfra-v2 3.4.0

1 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25

Open the chart page →

19,351
jenkinsbook-k8sinfra-v25.1.121 of 2See more

jenkins book-k8sinfra-v2 5.1.12

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

8,346
flaresolverrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

flaresolverr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
openssl@3.0.20-1~deb12u1
no fix listed

Open the chart page →

27,655
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

3,075
node-appbryopsida0.5.12 of 2See more

node-app bryopsida 0.5.1

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

14,576
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
openssl@3.5.0-r0
3.5.7-r0

Open the chart page →

1,308
mariadbbysamioVerified publisher1.0.21 of 1See more

mariadb bysamio 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/mariadb:12.0.2607835cd628b
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11

Open the chart page →

2,958
caddycaddyVerified publisher0.0.41 of 1See more

caddy caddy 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/caddy:2.11.2-alpine834468128c76
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,677
kafkacagriekinVerified publisher0.2.01 of 2See more

kafka cagriekin 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
apache/kafka:4.1.0bff074a5d005
openssl@3.5.2-r0
3.5.7-r0

Open the chart page →

2,402
ct-singlecalltelemetry0.8.41 of 7See more

ct-single calltelemetry 0.8.4

1 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
calltelemetry/web:0.8.1-rc7205d13269e350
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

10,672
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
openssl@3.0.9-1
no fix listed

Open the chart page →

8,042
geoservercamptocamp20.0.31 of 12See more

geoserver camptocamp2 0.0.3

1 of the 12 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

88,699
httpd-ldapauth-proxycamptocamp31.0.21 of 1See more

httpd-ldapauth-proxy camptocamp3 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/httpd:2.4.631ae8051591a5
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

3,351
nginx-s3-gatewaycamptocamp31.0.01 of 1See more

nginx-s3-gateway camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss-202503313db8145349a3
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,079
puppetservercamptocamp31.0.11 of 2See more

puppetserver camptocamp3 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25

Open the chart page →

5,928
tetragon-policy-buildercamptocamp30.1.11 of 1See more

tetragon-policy-builder camptocamp3 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

10,862

Container images carrying it

2,146 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-42767.

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.