StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,282
of 17,790 indexed, latest versions
Container images
3,536
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,282 of 17,790 indexed charts deploy, on 3,536 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,323
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,190
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,282 by stars
ChartLatestAffected imagesRadar Score
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,524
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

978
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,752
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

982
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,159
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,004
lakefslakefsVerified publisher1.12.301 of 1See more

lakefs lakefs 1.12.30

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
treeverse/lakefs:1.86.0fb7a0d90f77e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

403
radarrpree-helm-chartsVerified publisher1.33.01 of 1See more

radarr pree-helm-charts 1.33.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/radarr:6.4.4.10684dc66c010c5d9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

225
sonarrpree-helm-chartsVerified publisher1.24.01 of 1See more

sonarr pree-helm-charts 1.24.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/sonarr:4.0.20.30121f19eb5e0f42
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

214
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:3.23fd791d74b689
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

153
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2api:3.86f56d239d280
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2auth:3.833ecfda16608
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2notifier:3.8f190a6212195
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2rulesengine:3.8259503496ff9
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2scheduler:3.8b1de2055c362
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2stream:3.81c8904a3bf67
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2timersengine:3.81bf35bfaf00c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2web:3.809989a26c8b7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2workflowengine:3.819fdfffdbba8
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

96,933
supabasetokens-studioVerified publisher1.0.07 of 14See more

supabase tokens-studio 1.0.0

7 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
library/kong:3.8.0712e407b20ea
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
supabase/edge-runtime:v1.59.0eff9c554d649
openssl@3.0.14-1~deb12u2
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
openssl@3.0.14-1~deb12u2
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
openssl@3.0.14-1~deb12u2
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

23,365
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

8,586
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

1,778
budibasebudibase0.0.0-master5 of 7See more

budibase budibase 0.0.0-master

5 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
openssl@3.5.7-r0
3.5.8-r0
budibase/database:2.1.0d90f656261c9
openssl@3.0.18-1~deb12u2
no fix listed
budibase/proxy:3.41.38d780b6ee602
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
budibase/worker:3.41.3de5e2e560ce8
openssl@3.5.7-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

10,856
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.25 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

5 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2f21fca343428
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
openssl@3.3.5-3.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
openssl@3.3.5-5.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
openssl@3.3.5-5.azl3
3.3.7-6

Open the chart page →

2,263
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,110
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

3,496
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

3,048
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.29

Open the chart page →

7,923
docker-registry-uijoxitVerified publisher1.1.41 of 1See more

docker-registry-ui joxit 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
joxit/docker-registry-ui:2.6.0bb5956a6b378
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

676
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,496
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

818
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,404
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,296
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,261
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,107
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,386
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15

Open the chart page →

1,284
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

1,124
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

814
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

3,124
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,503
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

11,449
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29

Open the chart page →

1,740
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,962
caddyalekcVerified publisher0.9.01 of 1See more

caddy alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/caddy:2.11.4-alpine5f5c8640aae0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

853
zigbee2mqttandrenarchyVerified publisher9.44.01 of 1See more

zigbee2mqtt andrenarchy 9.44.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.14.1fef0de769dcd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

183
sealed-secrets-webbakitoVerified publisher3.3.21 of 1See more

sealed-secrets-web bakito 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/bakito/sealed-secrets-web:v3.3.2cb4d892c61c3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

4,284
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,156
umamichristianhuthVerified publisher7.13.11 of 2See more

umami christianhuth 7.13.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,369
yopasscloudhippieVerified publisher9.16.01 of 1See more

yopass cloudhippie 9.16.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jhaals/yopass:14.9.0934e4f2c016f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

438
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

3,041
dependabot-gitlabdependabot-gitlabVerified publisher6.3.03 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/postgres:18.6-alpined3e1620b530c
openssl@3.5.7-r0
3.5.8-r0
pgautoupgrade/pgautoupgrade:18-alpine48b448825656
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,641
devtron-operatordevtron0.23.36 of 11See more

devtron-operator devtron 0.23.3

6 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
openssl@3.5.7-r0
3.5.8-r0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

33,180
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

3,675
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

5,403
hcloud-csihcloud2.23.01 of 6See more

hcloud-csi hcloud 2.23.0

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,666
envoy-gatewayhelmforgeVerified publisher2.1.02 of 3See more

envoy-gateway helmforge 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
openssl@3.5.5-r0
3.5.8-r0
mccutchen/go-httpbin:v2.15.024528cf5229d
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

2,419

Container images carrying it

3,536 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
photoprism/photoprism:240711-cefc6fd632ca74
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.15
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
openssl@3.5.4-r0
3.5.8-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
openssl@3.5.1-1
3.5.7-1~deb13u2
1
pk910/powfaucet:v2-stable3dcae6a62896
openssl@3.0.16-1~deb12u1
no fix listed
1
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
platform9community/admin-server:latestde3fa9b70df1
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
1
platform9community/api-gateway:latest40a4970de568
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
1
platform9community/customers-service:latest2089811e5cc6
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
1
platform9community/vets-service:latestd1165c94dfb3
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
1
platform9community/visits-service:latest8d11b50368c6
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
1
platzio/backend:v0.6.5d5e5972f344b
openssl@3.5.1-r0
3.5.8-r0
1
platzio/frontend:v0.6.073083749b46a
openssl@3.5.1-r0
3.5.8-r0
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm5
1
plexinc/pms-docker:1.43.3.10896-cb3ebc72d83a425ae9e13
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
openssl@1.0.2g-1ubuntu4.16
1.0.2g-1ubuntu4.20+esm18
1
pmoscode/excalidraw:v0.18.08ee61554699c
openssl@3.5.4-r0
3.5.8-r0
1
pococze/python-hello-elos:2.0.07a1aab425e51
openssl@3.0.14-1~deb12u2
no fix listed
1
polyaxon/polyaxon-api:2.16.42b55c3265a90
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
pomerium/verify:latestd1602f8c96a3
openssl@3.0.20-1~deb12u2
no fix listed
1
postgis/postgis:18-3.67e00e8c3539f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
powerdns/pdns-recursor-54:5.4.533aadc74a8d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
pozetroninc/keydb:v6.0.1653ae64f29da8
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10
1
praravind1801/helmimages:3.0.0f29d637b9ce1
openssl@3.0.11-1~deb12u2
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
openssl@3.0.13-1~deb12u1
no fix listed
1
prefecthq/prometheus-prefect-exporter:4.0.050d527a190ae
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
pretix/standalone:2026.7.05df3b7aa852e
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
privatebin/nginx-fpm-alpine:2.0.613290e2f04bf
openssl@3.5.7-r0
3.5.8-r0
1
probely/farcaster-onprem-agent:v3741b34e8166f
openssl@3.0.20-1~deb12u2
no fix listed
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
openssl@3.5.1-1
3.5.7-1~deb13u2
1
project2team4/react:latest3ff031a08887
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm5
1
projectsveltos/dashboard:v1.15.01380c9314dd4
openssl@3.5.7-r0
3.5.8-r0
1
prom/cloudwatch-exporter:v0.16.071c2e988af06
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.15
1
prompve/prometheus-pve-exporter:3.8.2e3d501a82df5
openssl@3.5.5-r0
3.5.8-r0
1
promzeus/redis-sentinel-gateway:v182f6d56e280b
openssl@3.0.14-1~deb12u2
no fix listed
1
providus/undefined:lateste0b9f03bcd98
openssl@3.5.5-r0
3.5.8-r0
1
prowlercloud/prowler-api:5.31.14f252d579be2
openssl@3.0.20-1~deb12u2
no fix listed
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
openssl@3.5.7-r0
3.5.8-r0
1
proxysql/proxysql:3.0.8947a7abad45b
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
proxysql/proxysql:2.7.3a4d6c35c2949
openssl@3.0.15-1~deb12u1
no fix listed
1
pschichtel/mindustry-server:v145.1b543e9c2d371
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.29
1
psorab/elibrary:latest53b68896c4ce
openssl@1.1.1f-1ubuntu2.18
1.1.1f-1ubuntu2.24+esm5
1
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5
1
pubeldev/prusa_exporter:2.0.01091665a020a
openssl@3.5.4-r0
3.5.8-r0
1
puppet/puppet-agent:7.14.00b6fd9a6b7da
openssl@1.1.1-1ubuntu2.1~18.04.15
1.1.1-1ubuntu2.1~18.04.23+esm10
1
qdrant/qdrant:v1.7.45f2a56b95266
openssl@3.0.11-1~deb12u2
no fix listed
1
qdrant/qdrant:v1.4.166ee661d5241
openssl@3.0.9-1
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
qmcgaw/gluetun:v3.41.11a5bf4b4820a
openssl@3.5.5-r0
3.5.8-r0
1
qonstrukt/php:8.4-v8-apache089af7925aa1
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.