StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,266
of 17,790 indexed, latest versions
Container images
3,495
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,266 of 17,790 indexed charts deploy, on 3,495 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,303
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,169
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,266 by stars
ChartLatestAffected imagesRadar Score
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,521
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

968
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,716
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

977
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,154
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,004
lakefslakefsVerified publisher1.12.301See more

lakefs lakefs 1.12.30

1 container image this version deploys carries CVE-2026-54874.

Container imageDigestPackageFixed in
treeverse/lakefs:1.86.0fb7a0d90f77e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

radarrpree-helm-chartsVerified publisher1.33.01 of 1See more

radarr pree-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/radarr:6.4.4.10684dc66c010c5d9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

225
sonarrpree-helm-chartsVerified publisher1.24.01 of 1See more

sonarr pree-helm-charts 1.24.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/sonarr:4.0.20.30121f19eb5e0f42
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

214
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:3.23fd791d74b689
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

153
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2api:3.86f56d239d280
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2auth:3.833ecfda16608
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2notifier:3.8f190a6212195
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2rulesengine:3.8259503496ff9
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2scheduler:3.8b1de2055c362
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2stream:3.81c8904a3bf67
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2timersengine:3.81bf35bfaf00c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2web:3.809989a26c8b7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2workflowengine:3.819fdfffdbba8
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.07 of 14See more

supabase tokens-studio 1.0.0

7 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
library/kong:3.8.0712e407b20ea
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
supabase/edge-runtime:v1.59.0eff9c554d649
openssl@3.0.14-1~deb12u2
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
openssl@3.0.14-1~deb12u2
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
openssl@3.0.14-1~deb12u2
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

8,530
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

1,749
budibasebudibase0.0.0-master5 of 7See more

budibase budibase 0.0.0-master

5 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
openssl@3.5.7-r0
3.5.8-r0
budibase/database:2.1.0d90f656261c9
openssl@3.0.18-1~deb12u2
no fix listed
budibase/proxy:3.41.38d780b6ee602
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
budibase/worker:3.41.3de5e2e560ce8
openssl@3.5.7-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

10,810
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.25 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

5 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2f21fca343428
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
openssl@3.3.5-3.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
openssl@3.3.5-5.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
openssl@3.3.5-5.azl3
3.3.7-6

Open the chart page →

2,235
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,110
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

3,493
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

3,037
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.29

Open the chart page →

7,896
docker-registry-uijoxitVerified publisher1.1.41 of 1See more

docker-registry-ui joxit 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
joxit/docker-registry-ui:2.6.0bb5956a6b378
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

675
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,490
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

806
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,399
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,291
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,255
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,101
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,380
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15

Open the chart page →

1,279
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

1,118
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

809
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

3,128
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

11,453
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29

Open the chart page →

1,737
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,951
caddyalekcVerified publisher0.9.01 of 1See more

caddy alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/caddy:2.11.4-alpine5f5c8640aae0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

846
zigbee2mqttandrenarchyVerified publisher9.44.01 of 1See more

zigbee2mqtt andrenarchy 9.44.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.14.1fef0de769dcd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

183
sealed-secrets-webbakitoVerified publisher3.3.21 of 1See more

sealed-secrets-web bakito 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/bakito/sealed-secrets-web:v3.3.2cb4d892c61c3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

4,281
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,154
umamichristianhuthVerified publisher7.13.11See more

umami christianhuth 7.13.1

1 container image this version deploys carries CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

yopasscloudhippieVerified publisher9.16.01See more

yopass cloudhippie 9.16.0

1 container image this version deploys carries CVE-2026-54874.

Container imageDigestPackageFixed in
jhaals/yopass:14.9.0934e4f2c016f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

3,024
dependabot-gitlabdependabot-gitlabVerified publisher6.3.03 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/postgres:18.6-alpined3e1620b530c
openssl@3.5.7-r0
3.5.8-r0
pgautoupgrade/pgautoupgrade:18-alpine48b448825656
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,604
devtron-operatordevtron0.23.36 of 11See more

devtron-operator devtron 0.23.3

6 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
openssl@3.5.7-r0
3.5.8-r0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

5,396
hcloud-csihcloud2.23.01 of 6See more

hcloud-csi hcloud 2.23.0

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,631
envoy-gatewayhelmforgeVerified publisher2.1.02 of 3See more

envoy-gateway helmforge 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
openssl@3.5.5-r0
3.5.8-r0
mccutchen/go-httpbin:v2.15.024528cf5229d
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

2,391

Container images carrying it

3,495 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
makeplane/plane-mcp-server:v0.3.071b7252adef0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
makersquad/harp-proxy:0.8.1a40dd258c527
openssl@3.0.15-1~deb12u1
no fix listed
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5
1
mancube/dagron-api:0.9.2102eb70d39cf
openssl@3.0.20-1~deb12u2
no fix listed
1
mancube/dagron-engine:0.9.2447e6e5b20ef
openssl@3.0.20-1~deb12u2
no fix listed
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
maponyacharles/sceptreai:postgresql-0.1.1258881351f309
openssl@3.5.7-r0
3.5.8-r0
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
maponyacharles/sceptreai:seaweedfs-0.1.127c8a525f08e9
openssl@3.5.7-r0
3.5.8-r0
1
maponyacharles/sceptreai:ui-0.1.127cd0f11c5e55
openssl@3.5.7-r0
3.5.8-r0
1
maptiler/server:4.8.07e206140057b
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5
1
marcoimme/oidcmock:latestb6035c0721a8
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
margays/eir:v1.7.22883fdd06fd7
openssl@3.0.17-1~deb12u3
no fix listed
1
mariusm/vingress:0.5.0b3db186c3d72
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
martinhelmich/typo3:12.4c83a4f3fd7ae
openssl@3.0.18-1~deb12u2
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
openssl@3.0.20-1~deb12u2
no fix listed
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
openssl@3.0.15-1~deb12u1
no fix listed
1
matterlabs/external-node:9734bf2-17870579939295dadc06bdf3b
openssl@3.0.14-1~deb12u2
no fix listed
1
matterlabs/external-node:v24.0.06cbfea4c694a
openssl@3.0.11-1~deb12u2
no fix listed
1
mattermost/mattermost-enterprise-edition:11.10.18501080cdfe0
openssl@3.0.20-1~deb12u2
no fix listed
1
mattermost/mattermost-enterprise-edition:11.7ca5e5553a767
openssl@3.0.20-1~deb12u2
no fix listed
1
mattermost/mattermost-team-edition:11.10.18285b96eb412
openssl@3.0.20-1~deb12u2
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
openssl@3.0.20-1~deb12u1
no fix listed
1
mawad98/backstage-pyactions:demo99422c56a274
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
1
mbround18/valheim:3.1.070bd4da591cd
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
1
mccutchen/go-httpbin:v2.15.024528cf5229d
openssl@3.0.14-1~deb12u2
no fix listed
1
mcpuse/inspector:latest91b25e3eb604
openssl@3.5.7-r0
3.5.8-r0
1
mcronce/oci-registry:v0.4.509519cd7bd2f
openssl@3.0.11-1~deb12u2
no fix listed
1
mediagis/nominatim:5.3.27923a8e67197
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
mediagis/nominatim:3.7c15e941485ef
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5
1
mediagis/nominatim:4.2d0eae7b51374
openssl@3.0.2-0ubuntu1.14
3.0.2-0ubuntu1.29
1
megaease/easegress:latestfad1c7452958
openssl@3.5.5-r0
3.5.8-r0
1
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
merlos/zookeeper:3.9.3a38fc7e09ed7
openssl@3.0.15-1~deb12u1
no fix listed
1
metabase/metabase:v0.63.1.124f150effd484
openssl@3.5.7-r0
3.5.8-r0
1
metacubex/mihomo:v1.19.29e1d7dadaa936
openssl@3.5.7-r0
3.5.8-r0
1
middlewareeng/middleware:0.3.1747d880812f1
openssl@3.0.16-1~deb12u1
no fix listed
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.29
1
milvusdb/milvus:v2.2.13a3a55e1c1497
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5
1
mindsdb/mindsdb:latest163011c09299
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
miniflux/miniflux:2.3.349d7b6098761
openssl@3.5.7-r0
3.5.8-r0
1
miniflux/miniflux:2.2.18a3ca6bbc1f74
openssl@3.5.5-r0
3.5.8-r0
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm5
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
openssl@3.0.15-1~deb12u1
no fix listed
1
miqm/session-scaler:0.1.0c5c211717d9b
openssl@3.0.11-1~deb12u2
no fix listed
1
missuo/deeplx:v1.2.232e492587678
openssl@3.5.6-r0
3.5.8-r0
1
mlikiowa/napcat-docker:latest1336a777f9a4
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.29
1
moby/buildkit:v0.31.0a095b3d11ce1
openssl@3.5.7-r0
3.5.8-r0
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
openssl@3.0.20-1~deb12u2
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
openssl@3.0.16-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.