StackRadar

CVE-2026-42767

Medium

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,947
of 17,805 indexed, latest versions
Container images
2,160
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42767 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 1,947 of 17,805 indexed charts deploy, on 2,160 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+53 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.5.3-1ubuntu3.4, 3.5.5-1ubuntu3.2+1 more1,522
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0633
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-42767CGA-6x2v-fqjw-hp38DEBIAN-CVE-2026-42767UBUNTU-CVE-2026-42767AZL-89922ECHO-86de-f803-ef79
Also known as
CGA-72qw-77pm-grmj, CGA-963c-vm8f-q6wx, CGA-fccf-f32f-qfjm, USN-8414-1

Charts affected

1,947 by stars
ChartLatestAffected imagesRadar Score
tarkatarkaOfficialVerified publisher0.4.12 of 4See more

tarka tarka 0.4.1

2 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka:0.4.1e8d3f1512f06
openssl@3.6.2-r2
3.6.3-r0
ghcr.io/tarkyaio/tarka-ui:0.4.1b2dfabe13cfe
openssl@3.6.2-r2
3.6.3-r0

Open the chart page →

1,584
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,112
giropops-senhas-prdtechpreta0.1.01 of 2See more

giropops-senhas-prd techpreta 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
nataliagranato/redis:v1.0.052bd9b79a8f2
openssl@3.3.1-r4
3.6.3-r0

Open the chart page →

915
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

6,302
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

2,040
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

4,230
pingmetektonops0.1.21 of 1See more

pingme tektonops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
khaliq/pingme:v0.2.749f96888d2ab
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,255
tbot-spiffe-daemon-setteleport-agent-kube18.11.11 of 1See more

tbot-spiffe-daemon-set teleport-agent-kube 18.11.1

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
public.ecr.aws/gravitational/tbot-distroless:18.11.1f64ff28fd9bd
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

383
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
openssl@3.0.2-0ubuntu1
3.0.2-0ubuntu1.25
xeladock/nginx2:latestc259a67b1dff
openssl@3.0.2-0ubuntu1
3.0.2-0ubuntu1.25

Open the chart page →

109,619
tensorzerotensorzero2026.6.02 of 2See more

tensorzero tensorzero 2026.6.0

2 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
tensorzero/gateway:2026.6.0c939db4f27e4
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2
tensorzero/ui:2026.6.0f2563d54724e
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

4,078
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
supabase/studio:latest94a2a9d2906e
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,887
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,884
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

11,781
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

4,460
chatqnatest-opea1.0.08 of 11See more

chatqna test-opea 1.0.0

8 of the 11 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
no fix listed
opea/chatqna:1.038c51b791efa
openssl@3.0.14-1~deb12u2
no fix listed
opea/embedding-tei:1.05c9639de61c1
openssl@3.0.14-1~deb12u2
no fix listed
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
no fix listed
opea/reranking-tei:1.0e48613afb191
openssl@3.0.14-1~deb12u2
no fix listed
opea/retriever-redis:1.0eb746b263705
openssl@3.0.14-1~deb12u2
no fix listed
redis/redis-stack:7.2.0-v91c5f43fddcdd
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

39,639
codegentest-opea1.0.04 of 5See more

codegen test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
no fix listed
opea/codegen:1.058f91683892d
openssl@3.0.14-1~deb12u2
no fix listed
opea/codegen-ui:1.02bee4eb66f3e
openssl@3.0.11-1~deb12u2
no fix listed
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

29,111
codetranstest-opea1.0.04 of 5See more

codetrans test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
no fix listed
opea/codetrans:1.0e2436483b73d
openssl@3.0.14-1~deb12u2
no fix listed
opea/codetrans-ui:1.03ef121f34610
openssl@3.0.11-1~deb12u2
no fix listed
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

28,683
docsumtest-opea1.0.04 of 5See more

docsum test-opea 1.0.0

4 of the 5 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
openssl@3.0.14-1~deb12u2
no fix listed
opea/docsum:1.03eaa91849512
openssl@3.0.14-1~deb12u2
no fix listed
opea/docsum-ui:1.07f854e9bffaf
openssl@3.0.11-1~deb12u2
no fix listed
opea/llm-docsum-tgi:1.002f9e8fa5d71
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

29,157
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,263
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,299
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

4,797
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25

Open the chart page →

5,710
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,063
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,276
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

9,713
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

2,330
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

2,330
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

4,443
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,445
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

20,465
codeth-chartsVerified publisher0.1.01 of 1See more

code th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
collabora/code:24.04.13.2.101dc4ab83977
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,305
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

4,021
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

10,215
openmeteo-exporterth-chartsVerified publisher0.1.61 of 1See more

openmeteo-exporter th-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
thelande/openmeteo_exporter:v1.0.77e9072ace15f
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

1,382
prusa-exporterth-chartsVerified publisher0.3.01 of 1See more

prusa-exporter th-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
pubeldev/prusa_exporter:2.0.01091665a020a
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

909
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
openssl@3.0.2-0ubuntu1.26
no fix listed
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

7,528
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

25,562
tiktikVerified publisher2026.8.262043231 of 1See more

tik tik 2026.8.26204323

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/metio/tik:2026.8.2618070677f9ee7821d7
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

353
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,822
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

5,665
todolist-charttodolist-chart0.1.73 of 10See more

todolist-chart todolist-chart 0.1.7

3 of the 10 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
openssl@3.5.1-1
3.5.6-1~deb13u2
erenozcan17/go_backend:v4.250b4f23422b6
openssl@3.5.1-r0
3.5.7-r0
erenozcan17/react_frontend:v4.56e1b14973f9b
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

7,083
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

3,216
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,114
token-servertoken-server1.0.91 of 1See more

token-server token-server 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
udhos/token-server:1.0.9728013f2fac1
openssl@3.5.2-r0
3.5.7-r0

Open the chart page →

1,247
netbirdtotmicro1.8.23 of 4See more

netbird totmicro 1.8.2

3 of the 4 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
netbirdio/management:0.60.252682e5f48f9
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
netbirdio/relay:0.60.2a10762533793
openssl@3.0.17-1~deb12u3
no fix listed
netbirdio/signal:0.60.267176bcbf6ab
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

6,081
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,671
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25

Open the chart page →

3,035
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,379
trident-protect-bxp-previewtrident-protect100.2511.0-bxp-preview1 of 3See more

trident-protect-bxp-preview trident-protect 100.2511.0-bxp-preview

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v1.0.058b9fac358bd
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

2,201
trident-protect-consoletrident-protect100.2608.0-console1 of 3See more

trident-protect-console trident-protect 100.2608.0-console

1 of the 3 container images this version deploys carry CVE-2026-42767.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,370

Container images carrying it

2,160 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.6-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
no fix listed
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.7-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.7-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.7-r0
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.