StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,245
of 17,803 indexed, latest versions
Container images
3,486
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,245 of 17,803 indexed charts deploy, on 3,486 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,300
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,163
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,245 by stars
ChartLatestAffected imagesRadar Score
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
openssl@3.0.18-1~deb12u2
no fix listed

Open the chart page →

4,275
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.84 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

4 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm10
jingking/geonetwork-hnap:4.2.843e74ab234e1
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
library/elasticsearch:7.17.1588c2ec10c7f2
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
library/kibana:7.17.150172f1c538e7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

34,936
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm5
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

16,870
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cloudflare/cloudflared:latest51c9cefcb456
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

9,097
knativegitlabVerified publisher0.10.03 of 10See more

knative gitlab 0.10.0

3 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
istio/node-agent-k8s:1.2.9268ab879ea51
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18
istio/pilot:1.2.9c09319753454
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18
istio/proxyv2:1.2.90c78be035e98
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

36,198
glassflow-etlglassflowVerified publisher0.5.217 of 16See more

glassflow-etl glassflow 0.5.21

7 of the 16 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
alpine/curl:latestb9c839d47281
openssl@3.5.7-r0
3.5.8-r0
library/nats:2.12.3-alpine88fe8e0e09d6
openssl@3.5.4-r0
3.5.8-r0
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0
natsio/nats-box:0.19.28031d190c7ee
openssl@3.5.4-r0
3.5.8-r0
natsio/nats-server-config-reloader:0.21.110ff229eaf52
openssl@3.5.4-r0
3.5.8-r0
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/glassflow/glassflow-notifier:v1.0.3d1b0ce10b513
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

12,125
pgbouncerglassflowVerified publisher0.1.01 of 1See more

pgbouncer glassflow 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/pgbouncer:1.23.192356da09704
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,297
postgresqlglassflowVerified publisher0.1.91 of 1See more

postgresql glassflow 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

494
glauthglauthVerified publisher0.3.172 of 2See more

glauth glauth 0.3.17

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
nouchka/sqlite3:latestd183308f201c
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

2,648
glpiglpi-chart0.1.13 of 3See more

glpi glpi-chart 0.1.1

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/phpmyadmin:latest3a8a8d6b5289
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
vdiogov/glpi-conteiner:latest6945f84f0058
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

12,399
gnp-stackgnp-stack0.0.54 of 14See more

gnp-stack gnp-stack 0.0.5

4 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grafana/grafana:12.2.135c41e0fd029
openssl@3.5.4-r0
3.5.8-r0
rancher/local-path-provisioner:v0.0.329289da488b07
openssl@3.5.1-r0
3.5.8-r0
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
openssl@3.5.5-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

7,689
platformgoofy-chart0.1.01 of 1See more

platform goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
devopsgoofy/k8s-platform:latestad865312099f
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,813
googly-logingoogly-login0.1.01 of 2See more

googly-login googly-login 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,667
Governify-Bluejaygovernify0.1.02 of 12See more

Governify-Bluejay governify 0.1.0

2 of the 12 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

22,665
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

24,462
jaegergpg-dev3.3.32 of 5See more

jaeger gpg-dev 3.3.3

2 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
library/cassandra:3.11.65aa8400b4b3b
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

19,351
kube-prometheus-stackgpg-dev84.0.02 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

2 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grafana/grafana:13.0.10f86bada30d6
openssl@3.5.5-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

4,302
kubernetes-dashboardgpg-dev7.5.01 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

1 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29

Open the chart page →

6,087
openclawgpg-dev1.5.361 of 2See more

openclaw gpg-dev 1.5.36

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,665
opentelemetry-demogpg-dev0.33.88 of 27See more

opentelemetry-demo gpg-dev 0.33.8

8 of the 27 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
openssl@3.0.13-1~deb12u1
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
openssl@3.0.14-1~deb12u2
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
openssl@3.0.14-1~deb12u2
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
openssl@3.0.14-1~deb12u2
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.29
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
openssl@3.0.11-1~deb12u2
no fix listed
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

49,501
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,280
velerogpg-dev12.0.01 of 1See more

velero gpg-dev 12.0.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
velero/velero:v1.18.0e4d1e79be2ee
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.29

Open the chart page →

1,569
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

15,820
grafana-cloud-onboardinggrafana0.4.71 of 5See more

grafana-cloud-onboarding grafana 0.4.7

1 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

4,681
grafana-samplinggrafana1.1.71 of 2See more

grafana-sampling grafana 1.1.7

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grafana/alloy:v1.11.38c7256f412fe
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15

Open the chart page →

3,381
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

8,281
synthetic-monitoring-agentgrafana-communityVerified publisher1.19.01 of 1See more

synthetic-monitoring-agent grafana-community 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grafana/synthetic-monitoring-agent:v0.65.0fe3e095283f0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

213
grafana-dashboard-convertergrafana-dashboard-converterVerified publisher0.3.101 of 1See more

grafana-dashboard-converter grafana-dashboard-converter 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

909
grapple-installergrapple-installer0.3.221 of 1See more

grapple-installer grapple-installer 0.3.22

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grpl/grapple-cli:0.2.127c00aafee6629
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.15

Open the chart page →

8,012
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.29

Open the chart page →

4,687
grayloggraylogVerified publisher1.0.22 of 4See more

graylog graylog 1.0.2

2 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
library/mongo:85211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

5,366
cc-spring-appgridgainVerified publisher1.0.61 of 1See more

cc-spring-app gridgain 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gridgain/cloud-connector:2025.5.15ab838d7d3cb
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,692
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

3,229
routergroundcover1.12.3755See more

router groundcover 1.12.375

5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
public.ecr.aws/groundcovercom/kong:3.9.3-mini-20260804-107dfd0693fc4
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
openssl@3.5.4-1~deb13u2+e1
3.5.7-1~deb13u2
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
openssl@3.5.4-1~deb13u2+e1
3.5.7-1~deb13u2
quay.io/groundcover/tools:20260719b705e0cbe171
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2

Open the chart page →

temporalgroundcover1.12.3752See more

temporal groundcover 1.12.375

2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
openssl@3.5.6-1~deb13u1+e1
3.5.7-1~deb13u2

Open the chart page →

gtmgtmVerified publisher1.0.21 of 1See more

gtm gtm 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

495
librechat-exporterhajowielandVerified publisher1.0.01 of 1See more

librechat-exporter hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,308
rag-apihajowielandVerified publisher1.0.01 of 1See more

rag-api hajowieland 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat-rag-api-dev-lite:latestf9f34c8ed688
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,723
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,434
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,254
hatchet-apihatchetOfficialVerified publisher0.19.01 of 4See more

hatchet-api hatchet 0.19.0

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,707
hatchet-hahatchetOfficialVerified publisher0.19.03 of 8See more

hatchet-ha hatchet 0.19.0

3 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
no fix listed
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

7,447
hatchet-stackhatchetOfficialVerified publisher0.19.03 of 8See more

hatchet-stack hatchet 0.19.0

3 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
no fix listed
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

7,447
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.29

Open the chart page →

9,233
hdx-oss-v2hdx-oss-v20.8.42 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

2 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.7-alpine258d43821508
openssl@3.5.4-r0
3.5.8-r0
library/mongo:5.0.14-focal50cae5081ab4
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

6,758
heliconehelicone0.1.423 of 14See more

helicone helicone 0.1.42

3 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
openssl@3.0.2-0ubuntu1.9
3.0.2-0ubuntu1.29
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm5
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
openssl@3.0.9-1
no fix listed

Open the chart page →

25,250
helixhelix1.4.32 of 2See more

helix helix 1.4.3

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
openssl@3.5.5-r0
3.5.8-r0
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

5,696
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

5,880
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nodejs@16.19.1-deb-1nodesource1
openssl@1.1.1-1ubuntu2.1~18.04.21
no fix listed
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

10,730
my_web1helm-chart-by-piyush0.1.01 of 1See more

my_web1 helm-chart-by-piyush 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,715

Container images carrying it

3,486 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/biru-scop/tenzu-front:latest16759fa523f8
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
openssl@3.5.0-r0
3.5.8-r0
1
ghcr.io/bitwarden/sm-operator:2.1.0846624161f32
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/booklore-app/booklore:v2.3.1d3d3af34bc2c
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/bouquet2/copilot-api-docker:v0.7.06b0507a20602
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/browsersec/kubebrowse-frontend:chore-improve-backbd6bea5e487c
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
openssl@3.5.0-r0
3.5.8-r0
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
openssl@3.5.0-r0
3.5.8-r0
1
ghcr.io/bryopsida/wireguard:mainab6815bdfe2f
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
openssl@3.0.13-1~deb12u1
no fix listed
1
ghcr.io/bulwarkmail/webmail:1.6.0f0a266506fcf
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/bysamio/casepack-api:0.31.00eb3ad229c2c
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/bysamio/casepack-docs:0.8.0443d9850a688
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/bysamio/casepack-spa:0.30.0129212faf248
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/cameri/nostream:main8726533b9e69
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
ghcr.io/caninehq/canine:latesta058034ca006
openssl@3.0.13-1~deb12u1
no fix listed
1
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.369b1d3c09cfa
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
openssl@3.0.17-1~deb12u2
no fix listed
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.0e7f9e8f1d565
openssl@3.0.17-1~deb12u2
no fix listed
1
ghcr.io/chgl/fhir-server-exporter:v3.0.18b7d58a342e94
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/chgl/magnifhir:v1.5.213f121613edd
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
ghcr.io/chroma-core/chroma:1.5.3cfd193653bd6
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/chronicleprotocol/ghost:0.78.5951d71162065
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/cloudprober/cloudprober:v0.14.540c6d960ae4f
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/cloudquery/cloudquery:6.40.040b804fce7f9
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/cloudscript-technology/dumpscript:v0.0.42-alpine-edgefce5b6fd161c
openssl@3.5.5-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.