StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,920
of 17,803 indexed, latest versions
Container images
2,150
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,920 of 17,803 indexed charts deploy, on 2,150 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,511
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0634
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,920 by stars
ChartLatestAffected imagesRadar Score
hyperglance-helmhyperglance-helmVerified publisher10.0.84 of 6See more

hyperglance-helm hyperglance-helm 10.0.8

4 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25
hyperglance/init:postgres9fd5faf1fe80
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25
hyperglance/init:apacheb2f8c6d52623
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25
hyperglance/postgresql-v2:10.0.8a05d73bb30e7
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

11,222
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25

Open the chart page →

7,262
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25

Open the chart page →

8,021
iam-eks-user-mapperiam-eks-user-mapper1.6.01 of 1See more

iam-eks-user-mapper iam-eks-user-mapper 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
openssl@3.5.1-1+deb13u1
3.5.6-1~deb13u2

Open the chart page →

1,700
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

6,072
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/nginx:1.27.1934d1acd5ca8
openssl@3.0.14-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2fac502149c40
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

12,223
icegateicegateVerified publisher0.1.13 of 3See more

icegate icegate 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/icegatetech/icegate-ingest:0.1.1bae3c441894a
openssl@3.0.19-1~deb12u2
no fix listed
ghcr.io/icegatetech/icegate-maintain:0.1.193e85b2b76ee
openssl@3.0.19-1~deb12u2
no fix listed
ghcr.io/icegatetech/icegate-query:0.1.17542b4e7fff2
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

4,632
multicaicoretechVerified publisher0.4.431 of 5See more

multica icoretech 0.4.43

1 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
pgvector/pgvector:pg17cf134a767f47
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,775
tolgeeicoretechVerified publisher0.49.11 of 3See more

tolgee icoretech 0.49.1

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/postgres:18.369e8582b781c
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

2,788
monitoring-stackict-platformVerified publisher0.4.03 of 13See more

monitoring-stack ict-platform 0.4.0

3 of the 13 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/memcached:1.6.39-alpinec8503d4491ed
openssl@3.5.4-r0
3.5.7-r0
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
openssl@3.5.4-r0
3.5.7-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

9,704
eoloserverihuertas2021-vmartinp2021-helm0.1.01 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.25

Open the chart page →

27,906
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

9,200
ikigaiikigai-chartVerified publisher0.0.92 of 58See more

ikigai ikigai-chart 0.0.9

2 of the 58 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
library/zookeeper:3.8-temurin55d1e5b2e601
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

108,761
ilum-hive-metastoreilumVerified publisher1.2.01 of 2See more

ilum-hive-metastore ilum 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,635
ilum-marquezilumVerified publisher6.7.03 of 3See more

ilum-marquez ilum 6.7.0

3 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
openssl@3.0.15-1~deb12u1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
openssl@3.0.18-1~deb12u2
no fix listed
ilum/marquez-web:0.53.2716437a51a6c
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

6,369
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

2,826
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,238
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

11,913
plausible-analyticsimioVerified publisher0.4.24 of 5See more

plausible-analytics imio 0.4.2

4 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
no fix listed
library/postgres:17.6-alpineef257d85f76e
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

10,763
smtp4devimioVerified publisher0.1.11 of 1See more

smtp4dev imio 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rnwood/smtp4dev:3.6.1912304153668
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,242
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.25

Open the chart page →

3,365
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.25

Open the chart page →

5,378
pgcatimprowisedVerified publisher0.1.01 of 1See more

pgcat improwised 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,824
proxysqlimprowisedVerified publisher1.0.01 of 1See more

proxysql improwised 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
improwised/proxysql:master-6b26e59-171765063828940522e8b7
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,536
infisical-agent-injectorinfisical-charts0.1.121 of 1See more

infisical-agent-injector infisical-charts 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
infisical/infisical-agent-injector:v0.1.12718dd5bee7cb
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

761
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
openssl@3.0.18-1~deb12u2
no fix listed
library/influxdb:1.12.3-datab0f9fc41ed79
openssl@3.0.18-1~deb12u2
no fix listed

Open the chart page →

6,026
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/influxdb:latestf75e48af0598
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,383
ai-stackinfracloud-chartsVerified publisher0.6.01 of 3See more

ai-stack infracloud-charts 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,317
chromadbinfracloud-chartsVerified publisher0.3.01 of 1See more

chromadb infracloud-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,317
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,120
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

2,924
innago-vault-k8s-role-operatorinnagoVerified publisher2.0.51 of 1See more

innago-vault-k8s-role-operator innago 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/innago-property-management/innago-vault-k8s-role-operator:2.0.0ed1c3fd04057
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,054
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25

Open the chart page →

10,583
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

3,153
intelowlintelowl-helm6.6.1-01-06-20263 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

3 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
openssl@3.0.19-1~deb12u2
no fix listed
intelowlproject/intelowl_nginx:v6.6.12f01e79b8064
openssl@3.5.4-r0
3.5.7-r0
library/redis:8.6.34d25e2fe601f
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

18,066
polkabtc-parachaininterlay0.2.411 of 4See more

polkabtc-parachain interlay 0.2.41

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
byrnedo/alpine-curl:latest7f0599d553e2
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

3,951
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

5,590
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

5,590
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

2,514
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25

Open the chart page →

3,819
daveit-at-mOfficialVerified publisher0.2.162 of 11See more

dave it-at-m 0.2.16

2 of the 11 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/postgresql:latest42a8200d3597
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

12,337
thehiveittrident-oss0.1.01 of 6See more

thehive ittrident-oss 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/cassandra:4.0093ee8ee5eb2
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

6,331
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.11
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

45,468
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

10,922
unifi-network-applicationjanip81-helm-chartsVerified publisher0.2.91 of 3See more

unifi-network-application janip81-helm-charts 0.2.9

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/mongo:7.0b6421fd6d1c5
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

2,196
janus-shieldjanus-shield1.0.01 of 2See more

janus-shield janus-shield 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
seoulorigin/janus-ml-sidecar:v3.192cbaad0c540
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

2,435
ja-shortenerja-shortenerVerified publisher0.1.01 of 2See more

ja-shortener ja-shortener 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
cr0hn/ja-shortener:v0.1.414482d0bc4a1
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

2,091
jasperjasperVerified publisher1.0.2032 of 2See more

jasper jasper 1.0.203

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
openssl@3.0.16-1~deb12u1
no fix listed
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,273
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,150
govee2mqttjeffrescVerified publisher0.1.11 of 1See more

govee2mqtt jeffresc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/wez/govee2mqtt:2026.03.25-ab9deb66a9d9fe330574
openssl@3.0.18-1~deb12u2
no fix listed

Open the chart page →

655

Container images carrying it

2,150 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-42767.

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.