StackRadar

CVE-2026-42770

Low

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,763
of 17,797 indexed, latest versions
Container images
1,978
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-42770 affecting package openssl for versions less than 3.3.7-4

Carried by container images the latest versions of 1,763 of 17,797 indexed charts deploy, on 1,978 images.

Affected packageAffected versionsFixed inImages
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-45
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+49 more3.0.2-0ubuntu1.25, 3.0.13-0ubuntu3.11, 3.0.20-1~deb12u2, 3.5.3-1ubuntu3.4+2 more1,340
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0633
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
OSV records
ALPINE-CVE-2026-42770CGA-48p6-q29j-wfgrDEBIAN-CVE-2026-42770UBUNTU-CVE-2026-42770AZL-92843
Also known as
CGA-76q6-x77g-f8w6, CGA-8f4j-7345-7rgx, CGA-m98w-7xrq-cqw4, USN-8414-1

Charts affected

1,763 by stars
ChartLatestAffected imagesRadar Score
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,635
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
openssl@3.0.18-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

2,500
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
openssl@3.0.18-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

2,143
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
openssl@3.0.2-0ubuntu1.16
no fix listed
3.0.2-0ubuntu1.25

Open the chart page →

14,218
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

11,622
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

7,714
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
hamzaarshad10/querypodpy:1.7154f38e8668e
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
murtazashah46/helmfile:latest4d11726cf803
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

13,813
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.11

Open the chart page →

2,152
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

1,311
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

2,692
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,565
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,160
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-42770.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
no fix listed

Open the chart page →

7,936

Container images carrying it

1,978 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
opendatacube/wps:latest80df355a660b
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25
1
openebs/lvm-driver:1.10.141f73aba7f31
openssl@3.5.1-r0
3.5.7-r0
1
openmined/syft-backend:0.9.5b72f74a68b32
openssl@3.4.1-r0
3.6.3-r0
1
openmined/syft-frontend:0.9.5d11524a3854a
openssl@3.4.1-r0
3.6.3-r0
1
openproject/hocuspocus:release-338001b288dc1359dfb5
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2
1
openresty/openresty:1.31.1.1-1-alpine-fatacd832254d9c
openssl@3.5.6-r0
3.5.7-r0
1
openvino/model_server:2025.2.11e7cd1d70cc1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.7-r0
1
outlinewiki/outline:0.82.0494dfb9249a6
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
owncloud/ocis:8.0.1b38fd8fdd58f
openssl@3.5.5-r0
3.5.7-r0
1
owncloud/server:10.16.274c53d341076
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25
1
owncloud/server:10.16.3b3f9efdcd7f7
openssl@3.0.2-0ubuntu1.25
no fix listed
1
pangeo/base-notebook:2024.01.155fbe688a4f80
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.25
1
penpotapp/backend:2.2.147853d9bb9dd
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
penpotapp/exporter:2.2.15c835ffd87ab
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
openssl@3.5.6-r0
3.5.7-r0
1
phan2410/dummy-service:0.0.89c6ed6de26ca
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
photoprism/photoprism:220629-jammy2954334adbda
openssl@3.0.2-0ubuntu1.5
3.0.2-0ubuntu1.25
1
photoprism/photoprism:260601650c6ad5a651
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.2
1
photoprism/photoprism:251130db16ee6b1ba3
openssl@3.5.3-1ubuntu2
3.5.3-1ubuntu3.4
1
photoprism/photoprism:240711-cefc6fd632ca74
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.11
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.7-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
openssl@3.5.1-1
3.5.6-1~deb13u2
1
pk910/powfaucet:v2-stable3dcae6a62896
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
platzio/backend:v0.6.5d5e5972f344b
openssl@3.5.1-r0
3.5.7-r0
1
platzio/frontend:v0.6.073083749b46a
openssl@3.5.1-r0
3.5.7-r0
1
pmoscode/excalidraw:v0.18.08ee61554699c
openssl@3.5.4-r0
3.5.7-r0
1
pococze/python-hello-elos:2.0.07a1aab425e51
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
1
praravind1801/helmimages:3.0.0f29d637b9ce1
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
openssl@3.5.1-1
3.5.6-1~deb13u2
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.11
1
prompve/prometheus-pve-exporter:3.8.2e3d501a82df5
openssl@3.5.5-r0
3.5.7-r0
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
1
providus/undefined:lateste0b9f03bcd98
openssl@3.5.5-r0
3.5.7-r0
1
proxysql/proxysql:3.0.8947a7abad45b
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
proxysql/proxysql:2.7.3a4d6c35c2949
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
pschichtel/mindustry-server:v145.1b543e9c2d371
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
pubeldev/prusa_exporter:2.0.01091665a020a
openssl@3.5.4-r0
3.5.7-r0
1
qdrant/qdrant:v1.7.45f2a56b95266
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
1
qdrant/qdrant:v1.4.166ee661d5241
openssl@3.0.9-1
3.0.20-1~deb12u2
1
qmcgaw/gluetun:v3.41.11a5bf4b4820a
openssl@3.5.5-r0
3.5.7-r0
1
quickwit/quickwit:v0.8.1d29332bdadcc
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
1
qumine/minecraft-server:v0.1.15c0b650d51132
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25
1
rabeh/apibootspring:1.0941007b6946e
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
radarbase/radar-push-endpoint:0.4.0e1758508e033
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.