StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,930
of 17,805 indexed, latest versions
Container images
2,133
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,930 of 17,805 indexed charts deploy, on 2,133 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,502
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0626
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,930 by stars
ChartLatestAffected imagesRadar Score
flaskDiaryptj-miniproject2.1.21 of 2See more

flaskDiary ptj-miniproject 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
freedom98/flask:k3.0d7ce1533f297
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,114
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

2,856
shortlypwVerified publisher1.1.71 of 2See more

shortly pw 1.1.7

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nginx:1.30.0-alpine3.23-slim2fb5d772cea6
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

500
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
openssl@3.0.9-1
no fix listed

Open the chart page →

14,648
mychartpythonweb0.1.01 of 1See more

mychart pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

12,676
mypythonpythonweb0.1.01 of 1See more

mypython pythonweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
qichenxu4pd/pythonexample:1.0f3a8502bc21b
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

12,676
unifiqaoruVerified publisher1.1.31 of 2See more

unifi qaoru 1.1.3

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/mongo:7.0-jammy84c4a18b60a0
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

3,487
qualys-caqualys-ca-helm3.1.01 of 1See more

qualys-ca qualys-ca-helm 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
nelssec/qualys-agent-bootstrapper:v2.1.05e471f0cdeaa
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.25

Open the chart page →

1,931
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

7,847
nginx-chartrabsnginx0.1.01 of 1See more

nginx-chart rabsnginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nginx:1.276784fb0834aa
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

4,454
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
apache/airflow:2.10.2-python3.9ce90bdc3d2af
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

21,370
app-configradar-baseVerified publisher1.7.21 of 1See more

app-config radar-base 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

2,094
catalog-serverradar-baseVerified publisher0.9.31 of 1See more

catalog-server radar-base 0.9.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

2,476
data-dashboard-backendradar-baseVerified publisher0.6.21 of 1See more

data-dashboard-backend radar-base 0.6.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

2,077
headlampradar-baseVerified publisher1.0.01 of 1See more

headlamp radar-base 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.43.05d03caa26df7
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

656
kubecostradar-baseVerified publisher1.0.02 of 7See more

kubecost radar-base 1.0.0

2 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
openssl@3.4.1-r0
3.6.3-r0
gcr.io/kubecost1/kubecost-network-costs:v0.17.6ab6a54c53fd8
openssl@3.3.2-r0
3.6.3-r0

Open the chart page →

9,625
management-portalradar-baseVerified publisher1.7.01 of 1See more

management-portal radar-base 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.2

Open the chart page →

3,236
radar-gatewayradar-baseVerified publisher1.9.01 of 2See more

radar-gateway radar-base 1.9.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

2,341
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
curlimages/curl:8.15.04026b29997dc
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

2,196
radar-integrationradar-baseVerified publisher0.9.01 of 1See more

radar-integration radar-base 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

2,913
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

2,523
radar-push-endpointradar-baseVerified publisher0.6.81 of 2See more

radar-push-endpoint radar-base 0.6.8

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
radarbase/radar-push-endpoint:0.4.0e1758508e033
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

3,077
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,509
radar-upload-connect-backendradar-baseVerified publisher0.9.11 of 1See more

radar-upload-connect-backend radar-base 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11

Open the chart page →

2,591
s3-proxyradar-baseVerified publisher0.6.01 of 1See more

s3-proxy radar-base 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.11

Open the chart page →

2,796
rauthy-helmrauthy-helmVerified publisher1.0.81 of 1See more

rauthy-helm rauthy-helm 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/sebadob/rauthy:0.35.2a73dbf58359f
openssl@3.0.20-1~deb12u1
no fix listed

Open the chart page →

494
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,862
sqpreadyset-sqp-nightly0.1.0-nightly.202604302 of 3See more

sqp readyset-sqp-nightly 0.1.0-nightly.20260430

2 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
readysettech/sqp:latest588f3507280e
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
readysettech/sqp-duckdb:latest67a83203ce60
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

3,548
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
sharanalwar/redchef-backend:latest8d3cab80df49
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

4,956
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25

Open the chart page →

4,258
redis-enforce-expireredis-enforce-expire1.0.01 of 1See more

redis-enforce-expire redis-enforce-expire 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
udhos/redis-enforce-expire:1.0.0615b6a7d742e
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,296
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

6,356
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

7,469
juicepassproxyretsamedocVerified publisher2026.2.41 of 1See more

juicepassproxy retsamedoc 2026.2.4

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,981
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

7,160
spoolmanretsamedocVerified publisher26.9.01 of 1See more

spoolman retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,823
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

4,808
revwallet-apirevwallet0.7.121 of 1See more

revwallet-api revwallet 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
arthurjguerra18/revwallet:v0.7.12f540af20b307
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

5,896
istio-helloworldrgnu1.0.12 of 2See more

istio-helloworld rgnu 1.0.1

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
istio/examples-helloworld-v1:latest328b237e4fb1
openssl@3.0.11-1~deb12u2
no fix listed
istio/examples-helloworld-v2:latest0a7f02b2c7c9
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

9,504
kube-web-viewrlex0.5.01 of 1See more

kube-web-view rlex 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
hjacobs/kube-web-view:23.8.0431f1bf013d0
openssl@3.0.9-1
no fix listed

Open the chart page →

4,953
runtimeclass-controllerrlex0.1.01 of 1See more

runtimeclass-controller rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

2,186
kresusrm3lVerified publisher0.2.12 of 3See more

kresus rm3l 0.2.1

2 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
openssl@3.0.16-1~deb12u1
no fix listed
bnjbvr/kresus:0.22.137e216b182c8
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

15,770
memosrm3lVerified publisher0.1.11 of 1See more

memos rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
neosmemo/memos:0.24c6defc2dfb98
openssl@3.5.0-r0
3.5.7-r0

Open the chart page →

1,622
networking-toolboxrm3lVerified publisher0.1.01 of 1See more

networking-toolbox rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
lissy93/networking-toolbox:latest700862839553
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

825
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,541
wg-easyrm3lVerified publisher0.2.01 of 1See more

wg-easy rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.7-r0

Open the chart page →

1,160
kubewatchrobusta3.5.01 of 1See more

kubewatch robusta 3.5.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
robustadev/kubewatch:v2.9.00457a51e36e8
openssl@3.3.2-r0
3.6.3-r0

Open the chart page →

1,855
matrix-stackrock8sVerified publisher0.8.13 of 7See more

matrix-stack rock8s 0.8.1

3 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/haproxy:3.1-alpine475863a372c9
openssl@3.5.6-r0
3.5.7-r0
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
openssl@3.0.15-1~deb12u1
no fix listed
ghcr.io/element-hq/matrix-authentication-service:0.14.0834ea54370f0
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

9,498
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

6,226
monitoringrocketchat-server0.0.172 of 9See more

monitoring rocketchat-server 0.0.17

2 of the 9 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
openssl@3.5.1-r0
3.5.7-r0
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

7,044

Container images carrying it

2,133 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-42767.

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.