StackRadar

CVE-2026-54872

Low

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,961
of 17,985 indexed, latest versions
Container images
2,998
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,961 of 17,985 indexed charts deploy, on 2,998 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,700
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2298
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-54872DEBIAN-CVE-2026-54872UBUNTU-CVE-2026-54872ECHO-1163-5842-15ed
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 8 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,961 by stars
ChartLatestAffected imagesRadar Score
ceph-exporterygqygq2Verified publisher1.0.01 of 1See more

ceph-exporter ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
digitalocean/ceph_exporter:latest3ba058e9a48d
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

6,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,894
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

2,577
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,887
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,901
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

637
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,836
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,003
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,129
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

9,659
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
openssl@3.0.2-0ubuntu1.30
no fix listed

Open the chart page →

6,257

Container images carrying it

2,998 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
crate/crate-operator:2.43.1ea396813f6f0
openssl@3.0.15-1~deb12u1
no fix listed
1
cribl/cribl:3.0.2762747cb6796
openssl@1.1.1-1ubuntu2.1~18.04.9
openssl1.0@1.0.2n-1ubuntu5.6
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7
1
crocodilestick/calibre-web-automated:v4.0.6c31a738b6d5e
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.16
1
cspconsole/config-provider:1.0.365524a26a6c23
openssl@3.0.19-1~deb12u2
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
openssl@3.0.19-1~deb12u2
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
openssl@3.0.19-1~deb12u2
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
openssl@3.0.19-1~deb12u2
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
openssl@3.0.17-1~deb12u3
no fix listed
1
curlimages/curl:8.12.194e9e444bcba
openssl@3.3.3-r0
3.3.7-r2
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u3
1
cyverse/irods-csi-driver:v0.12.0aa69d105b292
openssl@3.0.2-0ubuntu1.29
3.0.2-0ubuntu1.30
1
cznic/knot-resolver:v6.4.24ad2e1894b78
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
openssl@3.0.11-1~deb12u2
no fix listed
1
dagster/dagster-celery-k8s:1.13.2559d2013d2e85
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
dagster/dagster-cloud-agent:1.13.257c13aa1c9a7a
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
openssl@3.0.17-1~deb12u3
no fix listed
1
dannielkil/book-frontend:latest937993927694
openssl@3.0.14-1~deb12u2
no fix listed
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.16
1
darthsim/imgproxy:v3.26476cb08c816a
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
darthsim/imgproxy:latestb42304f5e2ed
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
daskdev/dask-notebook:1.1.0052630f5ca04
openssl@1.1.0g-2ubuntu4.3
1.1.1-1ubuntu2.1~18.04.23+esm11
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
openssl@1.1.1-1ubuntu2.1~18.04.21
openssl1.0@1.0.2n-1ubuntu5.11
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7
1
datadog/agent:6aad9994de6a7
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.16
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
openssl@3.0.11-1~deb12u2
no fix listed
1
datafuselabs/databend-query:v1.2.279a936843b85b4
openssl@3.0.11-1~deb12u2
no fix listed
1
datalayers/datalayers:v2.2.1017b292079239
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.30
1
datalust/seq:5.0.832-pre9c731bb207a6
openssl@1.0.2g-1ubuntu4.10
1.0.2g-1ubuntu4.20+esm19
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm6
1
datamate/seafile-professional:11.0.202dd66b722464
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.30
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
1
dbgate/dbgate:7.2.0-alpine287077002446
openssl@3.3.7-r0
3.3.7-r2
1
dbgate/dbgate:7.2.3f2dc7423ea88
openssl@3.0.20-1~deb12u2
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.30
1
ddosify/alaz:v0.12.0ea602056d9ce
openssl@3.0.13-1~deb12u1
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
openssl@3.0.11-1~deb12u2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
openssl@3.0.11-1~deb12u2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
openssl@3.0.11-1~deb12u2
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
openssl@3.0.11-1~deb12u2
no fix listed
1
decisionrules/ai-engine:latest557dea1373aa
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
deconzcommunity/deconz:2.29.2062de2362641
openssl@3.0.15-1~deb12u1
no fix listed
1
deconzcommunity/deconz:2.26.123c86008d73f
openssl@3.0.11-1~deb12u2
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
openssl@3.0.2-0ubuntu1.9
3.0.2-0ubuntu1.30
1
defectdojo/defectdojo-django:3.3.3006516f0f62086
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u3
1
dellcloud/category:distributed02fc234353a9
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm6
1
dellcloud/pages:1.04d2eb25b9225
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm6
1
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
openssl@3.0.18-1~deb12u2
no fix listed
1
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u3
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.