StackRadar

CVE-2026-54872

Low

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,961
of 17,985 indexed, latest versions
Container images
2,998
deployed by those charts
Fix available
3 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,961 of 17,985 indexed charts deploy, on 2,998 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more2,700
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2298
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm722
OSV records
ALPINE-CVE-2026-54872DEBIAN-CVE-2026-54872UBUNTU-CVE-2026-54872ECHO-1163-5842-15ed
Also known as
USN-8847-1, USN-8847-2
Trending
Rank 8 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,961 by stars
ChartLatestAffected imagesRadar Score
ceph-exporterygqygq2Verified publisher1.0.01 of 1See more

ceph-exporter ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
digitalocean/ceph_exporter:latest3ba058e9a48d
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

6,136
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,894
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm11

Open the chart page →

2,577
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

2,887
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,901
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

637
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,836
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,003
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,129
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6

Open the chart page →

9,659
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-54872.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
openssl@3.0.2-0ubuntu1.30
no fix listed

Open the chart page →

6,257

Container images carrying it

2,998 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
libretranslate/libretranslate:v1.9.61de2d7056bb8
openssl@3.0.18-1~deb12u2
no fix listed
1
lightbend/curl:7.47.0b0c9894ac8dd
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm19
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
openssl@1.1.1-1ubuntu2.1~18.04.15
openssl1.0@1.0.2n-1ubuntu5.8
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7
1
linuxserver/airsonic-advanced:11.1.4e9272f1fb326
openssl@3.3.7-r0
3.3.7-r2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
nodejs@14.17.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.9
openssl1.0@1.0.2n-1ubuntu5.6
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7
1
linuxserver/calibre-web:0.6.24241009026e6f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.16
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm6
1
linuxserver/code-server:4.10.1a5e43a05ae79
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.30
1
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.7
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm11
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
openssl@3.3.3-r0
3.3.7-r2
1
linuxserver/deluge:18.04.10ac871624394
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
openssl@1.1.1-1ubuntu2.1~18.04.13
1.1.1-1ubuntu2.1~18.04.23+esm11
1
linuxserver/foldingathome:7.6.219a997426d71e
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.16
1
linuxserver/foldingathome:8.5.6ebb32940e4bb
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
linuxserver/jackett:0.20.39922b8bfdee1ae
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
1
linuxserver/jellyfin:10.7.72427dde159a2
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm6
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm11
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
openssl@1.1.0g-2ubuntu4.3
openssl1.0@1.0.2n-1ubuntu5.3
1.1.1-1ubuntu2.1~18.04.23+esm11
1.0.2n-1ubuntu5.13+esm7
1
linuxserver/plex:1.43.22785a6ad64d3
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.16
1
linuxserver/plex:1.25.24a13ced2326c
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
linuxserver/radarr:3.2.25965bbb2f90d
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
linuxserver/sonarr:3.0.6b5a31ff4fdf3
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm11
1
linuxserver/unifi-controller:8.0.240ae315a3a456
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm6
1
linuxserver/unifi-controller:7.3.83ab105cc50322
openssl@1.1.1f-1ubuntu2.18
1.1.1f-1ubuntu2.24+esm6
1
linuxserver/unifi-network-application:10.6.106-ls1467f15f34937ce
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
lis314/project-zomboid-docker:latestaa2089c37920
openssl@3.0.15-1~deb12u1
no fix listed
1
litmuschaos/mongo:4.2.899961210d467
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm11
1
livekit/ingress:v1.2.21ab01641b366
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.30
1
lmacka/snappass:2.1.293f5c048b7d4
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u3
1
localstack/localstack:3.19d278167f2b7
openssl@3.0.11-1~deb12u2
no fix listed
1
localstack/localstack:latestdf6b89814326
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
locustio/locust:2.24.151d866285170
openssl@3.0.11-1~deb12u2
no fix listed
1
loeken/radarr:5.27.0-nightlya24409d3846d
openssl@3.3.4-r0
3.3.7-r2
1
log10x/filebeat-10x:1.1.39-native7d6a79dacd58
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm6
1
logiqai/flash:v3.10.265b996bc7bdc
openssl@3.0.14-1~deb12u2
no fix listed
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm11
1
louislam/its-mytabs:1.7.02e478d3170bd
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
openssl@3.0.18-1~deb12u2
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
openssl@3.0.17-1~deb12u3
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
openssl@3.0.20-1~deb12u1
no fix listed
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
openssl@3.0.17-1~deb12u3
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
lucassandin/welcome-api:latest04551c5d5881
openssl@3.0.11-1~deb12u2
no fix listed
1
luligu/matterbridge:3.0.28f97884bebc2
openssl@3.0.15-1~deb12u1
no fix listed
1
luligu/matterbridge:3.10.11e278cf685f91
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
lumenvox/cloud-audit:2.0.079428add7f38
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm6
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.