StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,263
of 17,803 indexed, latest versions
Container images
3,507
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,263 of 17,803 indexed charts deploy, on 3,507 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,308
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,176
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,263 by stars
ChartLatestAffected imagesRadar Score
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,710
offline-license-serverappscodeVerified publisher2026.9.112 of 2See more

offline-license-server appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/maxmind-geoip:city-mmdb-latesta3236324c4e2
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,692
operator-shard-managerappscodeVerified publisher2026.6.221 of 1See more

operator-shard-manager appscode 2026.6.22

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/operator-shard-manager:v0.0.64a16c6ccecb8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

425
outbox-syncerappscodeVerified publisher2026.9.111 of 1See more

outbox-syncer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/outboxsyncer:v0.5.0150baab6115d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

346
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,566
pgoutboxappscodeVerified publisher2026.7.101 of 1See more

pgoutbox appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/pgoutbox:v0.0.4a96e06ec5e9f
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

843
platform-apiappscodeVerified publisher2026.9.113 of 3See more

platform-api appscode 2026.9.11

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
ghcr.io/appscode/maxmind-geoip:city-mmdb-latesta3236324c4e2
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

37,889
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

702
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

658
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29

Open the chart page →

3,326
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

553
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,344
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,197
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,252
sidekickappscodeVerified publisher2026.7.101 of 1See more

sidekick appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/sidekick:v0.0.16d8d2a3c22ee7
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

286
storage-metrics-serverappscodeVerified publisher2026.7.81 of 1See more

storage-metrics-server appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

560
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,091
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,227
voyager-gatewayappscodeVerified publisher2026.7.211 of 2See more

voyager-gateway appscode 2026.7.21

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,373
websiteappscodeVerified publisher2026.9.111 of 1See more

website appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/website:v2026.9.1170d9d1b78d39
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

371
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
openssl@3.0.9-1
no fix listed

Open the chart page →

5,704
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

8,931
appwriteappwrite-helmVerified publisher1.3.22 of 8See more

appwrite appwrite-helm 1.3.2

2 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
openssl@3.5.5-r0
3.5.8-r0
clamav/clamav:1.0dd0d9cc746af
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

9,855
arcadearcadeVerified publisher1.10.12 of 10See more

arcade arcade 1.10.1

2 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0
library/redis:8-alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

991
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

7,607
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

7,697
argonix-apiargonix0.2.91 of 4See more

argonix-api argonix 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0a584153dfae5
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

4,999
arlas-aiasarlas-stackVerified publisher28.8.012 of 22See more

arlas-aias arlas-stack 28.8.0

12 of the 22 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
openssl@3.0.16-1~deb12u1
no fix listed
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
openssl@3.0.16-1~deb12u1
no fix listed
gisaia/arlas-wui:28.0.3b83b3e067173
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

41,099
arlas-uisarlas-stackVerified publisher28.8.03 of 4See more

arlas-uis arlas-stack 28.8.0

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gisaia/arlas-wui:28.0.3b83b3e067173
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,960
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

23,461
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

3,703
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

22,754
assemblylineassemblylineVerified publisher7.4.206 of 12See more

assemblyline assemblyline 7.4.20

6 of the 12 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable20098127270065
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-rust:4.7.4.stable202be5e6a57427
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-socketio:4.7.4.stable202b88493b62f7
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui:4.7.4.stable20efa75509b854
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui-frontend:4.7.4.stable208f3de0b45727
openssl@3.5.7-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

12,862
dltkvassist-iot-data-integrity-verification0.2.03 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

185,703
dltflassist-iot-dlt-based-fl0.2.03 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

185,703
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

9,428
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

13,413
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

10,179
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

83,638
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

8,072
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

7,986
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

5,382
smartorchestratorassist-iot-smart-orchestrator4.0.05 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

5 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssl@3.0.9-1
no fix listed
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

45,972
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5
bluenviron/mediamtx:latest-ffmpeg9d148b5f2990
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

72,862
account-monitorastria0.0.11 of 1See more

account-monitor astria 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,978
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.29
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

32,715
auctioneerastria0.0.21 of 1See more

auctioneer astria 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,227
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

3,309
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,203
evm-rollupastria4.1.02 of 2See more

evm-rollup astria 4.1.0

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.8-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

4,038

Container images carrying it

3,507 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/k8snetworkplumbingwg/multus-cni:latest-thickb2136983532b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/k8snetworkplumbingwg/multus-cni:stableec4e5dfe12b6
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.4f279fd7dc112
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/k8up-io/k8up:v2.16.029458113b8b6
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/keiailab/nodevitals:0.8.597107e46f0d3
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/klicktipp/csa-exporter:0.3.12c69513f9d85
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/klicktipp/snds-exporter:v0.2.4a23b389cb3c5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/kluster-manager/fluxcd-addon:v0.0.103475404bef5c
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/klustrefs/klustre-csi-plugin:0.1.1bcf42ccda0f9
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/kokuwaio/pingdom-exporter:v0.5.73e52df096943
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10
1
ghcr.io/kozea/radicale:3.7.600a3d8e1f04b
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/kubedb/kubedb-courier:v0.6.02f88856584a8
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/kubedb/kubedb-gitops:v0.14.0c743f8d7a199
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/kubedb/migrator-operator:v0.5.098ffb48f5b60
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/kubelauncher/cassandrab66aba320083
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/etcd8ab954711fb9
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/keycloakafe3bd73d7cf
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/kubectl7280594a2f18
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/mariadbe25056a6ec52
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/mongodb9bc37ed78a8b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/mysqle9609bd50416
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/openldap8978aa002bc0
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/kubelauncher/postgresql1a27e11e5925
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubelauncher/rabbitmqff5a36a457f1
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
ghcr.io/kubelauncher/redisbcd8e9a6224f
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
ghcr.io/kubereboot/kured:1.23.08dfd3c2e8893
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/kubestellar/console:v0.3.41457cfc94b4da
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/kubevault/vault-operator:v0.24.00087cb49616f
openssl@3.0.19-1~deb12u2
no fix listed
1
ghcr.io/kubevoip/kubevoip:v0.6.841c603a93642
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2
1
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/kuoss/lethe:v0.3.3ebdf55fd5705
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/kuoss/venti:v0.3.38ee3e70d77f1
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm5
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm5
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.