CVE-2026-54872
LowAdvisory
Published 29 Sept 2026In the index since 30 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.7
- base score, highest
- EPSS
- 0.003
- 16th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,961
- of 17,985 indexed, latest versions
- Container images
- 2,998
- deployed by those charts
- Fix available
- 3 of 4
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 2,961 of 17,985 indexed charts deploy, on 2,998 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more | 1.0.1f-1ubuntu2.27+esm17, 1.0.2g-1ubuntu4.20+esm19, 1.1.1-1ubuntu2.1~18.04.23+esm11, 1.1.1f-1ubuntu2.24+esm6+4 more | 2,700 |
| opensslapk | 3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more | 3.3.7-r2 | 298 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 more | no fix listed | 23 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more | 1.0.2n-1ubuntu5.13+esm7 | 22 |
- OSV records
- ALPINE-CVE-2026-54872DEBIAN-CVE-2026-54872UBUNTU-CVE-2026-54872ECHO-1163-5842-15ed
- Also known as
- USN-8847-1, USN-8847-2
- Trending
- Rank 8 in indexed charts, since 30 Sept 2026. See the ranking →
Charts affected
2,961 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| ceph-exporterygqygq2Verified publisher | 1.0.0 | 1 of 1See more | 6,136 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,894 |
| zahori-schedulerzahoriVerified publisher | 1.0.1 | 1 of 1See more | 2,577 |
| jenkinszanise-jenkins-helm-chart | 0.1.0 | 1 of 1See more | 2,887 |
| changedetection-iozekker6Verified publisher | 1.103.0 | 1 of 1See more | 2,901 |
| endlessh-gozekker6Verified publisher | 0.4.0 | 1 of 1See more | 637 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,836 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 5,003 |
| zimagizimagi | 2.7.17 | 1 of 6See more | 2,129 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,659 |
| zoo-project-druzoo-projectOfficialVerified publisher | 0.10.8 | 1 of 6See more | 6,257 |
Container images carrying it
2,998 by charts deploying them
A fixed version is listed for 3 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| opea/ | 25dd26d9cd09 | openssl | no fix listed | 1 |
| opea/ | 38c51b791efa | openssl | no fix listed | 1 |
| opea/ | 58f91683892d | openssl | no fix listed | 1 |
| opea/ | 2bee4eb66f3e | openssl | no fix listed | 1 |
| opea/ | e2436483b73d | openssl | no fix listed | 1 |
| opea/ | 3ef121f34610 | openssl | no fix listed | 1 |
| opea/ | 3eaa91849512 | openssl | no fix listed | 1 |
| opea/ | 7f854e9bffaf | openssl | no fix listed | 1 |
| opea/ | 262c6048aab8 | openssl | no fix listed | 1 |
| opea/ | f68bec6a1271 | openssl | no fix listed | 1 |
| opea/ | 02f9e8fa5d71 | openssl | no fix listed | 1 |
| opea/ | 249afad3d268 | openssl | no fix listed | 1 |
| opea/ | 257ae94709e9 | openssl | no fix listed | 1 |
| opea/ | fe08165d7770 | openssl | no fix listed | 1 |
| openaev/ | 6c512196d956 | openssl | 3.0.13-0ubuntu3.16 | 1 |
| openbas/ | a277796d9724 | openssl | no fix listed | 1 |
| openbas/ | d986d80b0a75 | openssl | 3.0.13-0ubuntu3.16 | 1 |
| opencsghq/ | 41cba9c366f1 | openssl | no fix listed | 1 |
| opencsghq/ | 7d0271e26521 | openssl | 3.5.7-1~deb13u3 | 1 |
| opencsghq/ | 1cb36b49151e | openssl | no fix listed | 1 |
| opencsghq/ | 587046575c2c | openssl | no fix listed | 1 |
| opencsghq/ | 86ea22f495c7 | openssl | no fix listed | 1 |
| opencsghq/ | 865814dc87a1 | openssl | 3.3.7-r2 | 1 |
| opencsghq/ | bdd2c58b9744 | openssl | no fix listed | 1 |
| opencsghq/ | 80a65ac370da | openssl | no fix listed | 1 |
| opendatacube/ | 668cbb41473c | openssl | 3.0.13-0ubuntu3.16 | 1 |
| opendatacube/ | 5d810e8504b8 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm11 | 1 |
| opendatacube/ | 91870111837c | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm11 | 1 |
| opendatacube/ | 1b90cdf68831 | openssl | 1.1.1-1ubuntu2.1~18.04.23+esm11 | 1 |
| opendatacube/ | 80df355a660b | openssl | 3.0.2-0ubuntu1.30 | 1 |
| opendronemap/ | fcd99eb23d8d | openssl | 3.0.13-0ubuntu3.16 | 1 |
| openebs/ | 96fd7987ea79 | openssl | 3.5.7-1~deb13u3 | 1 |
| openelevation/ | 82fb21612e86 | openssl | 1.1.1f-1ubuntu2.24+esm6 | 1 |
| openhab/ | bfd4a60e90da | openssl | 3.5.7-1~deb13u3 | 1 |
| openkm/ | 3bc465a7461b | openssl | 1.1.1f-1ubuntu2.24+esm6 | 1 |
| openkruise/ | 0482722b4e56 | openssl | 3.3.7-r2 | 1 |
| openkruise/ | f81ae78a36a4 | openssl | 3.3.7-r2 | 1 |
| opennode/ | 4c82b15d9042 | openssl | 3.5.7-1~deb13u3 | 1 |
| openproject/ | 88dc1359dfb5 | openssl | no fix listed | 1 |
| opensearchproject/ | 43b0cdaf26ed | openssl | 1.1.1f-1ubuntu2.24+esm6 | 1 |
| openstackhelm/ | f728510bab3c | openssl | 1.1.1f-1ubuntu2.24+esm6 | 1 |
| openstackhelm/ | e07d75953d2e | openssl | 1.1.1f-1ubuntu2.24+esm6 | 1 |
| openthread/ | 7616b9d514de | openssl | 3.0.13-0ubuntu3.16 | 1 |
| openthread/ | 35c6e6520080 | nodejs openssl openssl1.0 | no fix listed 1.1.1-1ubuntu2.1~18.04.23+esm11 1.0.2n-1ubuntu5.13+esm7 | 1 |
| openvino/ | 1e7cd1d70cc1 | openssl | 3.0.13-0ubuntu3.16 | 1 |
| openvpn/ | 2253c10ec652 | openssl | 3.0.13-0ubuntu3.16 | 1 |
| openwhisk/ | c80dba0de3aa | nodejs openssl openssl1.0 | no fix listed 1.1.1-1ubuntu2.1~18.04.23+esm11 1.0.2n-1ubuntu5.13+esm7 | 1 |
| operaton/ | b35867ffe4d8 | openssl | 3.3.7-r2 | 1 |
| opsmx11/ | 5c50ca123d88 | openssl | 1.0.1f-1ubuntu2.27+esm17 | 1 |
| orbitalreg/ | 4fd449582a3c | openssl | 3.3.7-r2 | 1 |