StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,930
of 17,805 indexed, latest versions
Container images
2,133
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,930 of 17,805 indexed charts deploy, on 2,133 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,502
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0626
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,930 by stars
ChartLatestAffected imagesRadar Score
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

5,785
jaegerromanow-helm-chartsVerified publisher1.7.31 of 1See more

jaeger romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
jaegertracing/jaeger:2.9.0e128b9adbb29
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

1,623
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

9,743
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25

Open the chart page →

13,159
devtron-enterpriseromholdings48.0.03 of 28See more

devtron-enterprise romholdings 48.0.0

3 of the 28 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

69,552
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

4,983
devtron-operatorromholdings0.23.32 of 11See more

devtron-operator romholdings 0.23.3

2 of the 11 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

33,352
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,947
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rommapp/romm:5.2.03512f2ca4557
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

3,441
acme-linoderotationalVerified publisher1.0.41 of 1See more

acme-linode rotational 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/linode-acme-webhook:1.0.0cc7bb030a20f
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,324
endeavorrotationalVerified publisher1.3.12 of 2See more

endeavor rotational 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/endeavor:1.3.0ac566baddc06
openssl@3.0.20-1~deb12u2
no fix listed
rotationalio/quarterdeck:0.16.00e7ad3a031dc
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,291
geopingrotationalVerified publisher1.3.21 of 1See more

geoping rotational 1.3.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/geoping:1.3.034bcb6fc3cb7
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,618
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,206
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,355
quarterdeckrotationalVerified publisher0.16.01 of 1See more

quarterdeck rotational 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/quarterdeck:0.16.00e7ad3a031dc
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,187
rotational-apirotationalVerified publisher1.3.11 of 1See more

rotational-api rotational 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/rotational-api:1.3.0f1a2d05d8fff
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,617
vanityrotationalVerified publisher1.2.21 of 1See more

vanity rotational 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
rotationalio/vanity:1.2.0d77350f69b45
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,247
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,566
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

4,772
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
openssl@3.5.2-r0
3.5.7-r0

Open the chart page →

4,760
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
quay.io/curl/curl:8.16.0b17b13321678
openssl@3.5.2-r0
3.5.7-r0

Open the chart page →

4,760
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25

Open the chart page →

7,759
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

5,359
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

10,680
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

4,575
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,734
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
openssl@3.0.20-1~deb12u1
no fix listed

Open the chart page →

27,754
glancerubxkubeVerified publisher0.1.11 of 1See more

glance rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.532ab73d80f2b
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

764
jackettrubxkubeVerified publisher1.4.11 of 1See more

jackett rubxkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
linuxserver/jackett:0.24.2066f1f23e0c9845
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

498
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

2,658
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

7,500
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

6,296
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
openssl@3.0.20-1~deb12u1
no fix listed

Open the chart page →

30,706
your-spotifyrubxkubeVerified publisher1.0.13 of 3See more

your-spotify rubxkube 1.0.1

3 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
openssl@3.0.16-1~deb12u1
no fix listed
yooooomi/your_spotify_client:1.20.0e4da90a0634c
openssl@3.5.6-r0
3.5.7-r0
yooooomi/your_spotify_server:1.20.0624ea009f2ef
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

5,463
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

5,903
janitorrryuunosukeds30.1.31 of 1See more

janitorr ryuunosukeds3 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

1,003
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25

Open the chart page →

8,790
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
openssl@3.5.1-1+deb13u1
3.5.6-1~deb13u2

Open the chart page →

9,763
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25

Open the chart page →

7,478
s3-browsers3-browser0.4.11 of 1See more

s3-browser s3-browser 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

587
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,932
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssl@3.0.9-1
no fix listed

Open the chart page →

19,777
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
openssl@3.0.9-1
no fix listed

Open the chart page →

16,779
sagawisesagawiseVerified publisher0.1.01 of 3See more

sagawise sagawise 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
venturenox/redis:latest83b471c193ba
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

4,383
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.25

Open the chart page →

16,274
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.25

Open the chart page →

8,152
evsantisbon0.2.02 of 5See more

ev santisbon 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
santisbon/evwatcher:latestc4e994ca4540
openssl@3.0.9-1
no fix listed
santisbon/evworker:lateste807283f8d69
openssl@3.0.9-1
no fix listed

Open the chart page →

14,355
speedtestsantisbon0.1.02 of 3See more

speedtest santisbon 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
openssl@3.0.19-1~deb12u2
no fix listed
santisbon/speedtest:latest8ee3a1697227
openssl@3.0.9-1
no fix listed

Open the chart page →

12,826
airflowsb-helm-charts0.3.01 of 1See more

airflow sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
apache/airflow:2.8.1e5560ad0b86e
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

10,269
grafanasb-helm-charts0.4.01 of 1See more

grafana sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
grafana/grafana:12.2.22ebef928d7e5
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,829

Container images carrying it

2,133 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-42767.

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.