StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,263
of 17,803 indexed, latest versions
Container images
3,507
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,263 of 17,803 indexed charts deploy, on 3,507 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,308
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,176
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,263 by stars
ChartLatestAffected imagesRadar Score
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,004
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,798
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

997
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,174
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,018
lakefslakefsVerified publisher1.12.301 of 1See more

lakefs lakefs 1.12.30

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
treeverse/lakefs:1.86.0fb7a0d90f77e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

405
radarrpree-helm-chartsVerified publisher1.34.01 of 1See more

radarr pree-helm-charts 1.34.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/radarr:6.4.4.10685be53998a2d39
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

225
sonarrpree-helm-chartsVerified publisher1.24.01 of 1See more

sonarr pree-helm-charts 1.24.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/sonarr:4.0.20.30121f19eb5e0f42
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

214
questdbquestdb1.0.271 of 2See more

questdb questdb 1.0.27

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:3.23fd791d74b689
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

153
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2api:3.86f56d239d280
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2auth:3.833ecfda16608
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2notifier:3.8f190a6212195
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2rulesengine:3.8259503496ff9
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2scheduler:3.8b1de2055c362
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2stream:3.81c8904a3bf67
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2timersengine:3.81bf35bfaf00c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2web:3.809989a26c8b7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
stackstorm/st2workflowengine:3.819fdfffdbba8
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

690,249
supabasetokens-studioVerified publisher1.0.07 of 14See more

supabase tokens-studio 1.0.0

7 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
library/kong:3.8.0712e407b20ea
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
supabase/edge-runtime:v1.59.0eff9c554d649
openssl@3.0.14-1~deb12u2
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
openssl@3.0.14-1~deb12u2
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
openssl@3.0.14-1~deb12u2
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

23,508
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

8,625
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

1,832
budibasebudibase0.0.0-master5 of 7See more

budibase budibase 0.0.0-master

5 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
openssl@3.5.7-r0
3.5.8-r0
budibase/database:2.1.0d90f656261c9
openssl@3.0.18-1~deb12u2
no fix listed
budibase/proxy:3.41.38d780b6ee602
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
budibase/worker:3.41.3de5e2e560ce8
openssl@3.5.7-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

11,231
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.25 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

5 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2f21fca343428
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
openssl@3.3.5-3.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
openssl@3.3.5-5.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
openssl@3.3.5-5.azl3
3.3.7-6

Open the chart page →

2,327
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,113
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

3,509
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

3,074
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.29

Open the chart page →

7,973
docker-registry-uijoxitVerified publisher1.1.41 of 1See more

docker-registry-ui joxit 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
joxit/docker-registry-ui:2.6.0bb5956a6b378
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

676
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,556
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

839
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,452
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,348
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,277
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,121
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,400
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15

Open the chart page →

1,299
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

1,138
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

828
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

3,175
quickwitquickwit0.8.171 of 1See more

quickwit quickwit 0.8.17

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

3,526
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

11,597
zillazillaOfficialVerified publisher2.4.31 of 1See more

zilla zilla 2.4.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29

Open the chart page →

1,750
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,000
caddyalekcVerified publisher0.9.01 of 1See more

caddy alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/caddy:2.11.4-alpine5f5c8640aae0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

863
zigbee2mqttandrenarchyVerified publisher9.44.01 of 1See more

zigbee2mqtt andrenarchy 9.44.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.14.1fef0de769dcd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

183
sealed-secrets-webbakitoVerified publisher3.3.21 of 1See more

sealed-secrets-web bakito 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/bakito/sealed-secrets-web:v3.3.2cb4d892c61c3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

4,288
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,157
umamichristianhuthVerified publisher7.13.11 of 2See more

umami christianhuth 7.13.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,364
yopasscloudhippieVerified publisher9.16.01 of 1See more

yopass cloudhippie 9.16.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jhaals/yopass:14.9.0934e4f2c016f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

450
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

3,067
dependabot-gitlabdependabot-gitlabVerified publisher6.3.03 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/postgres:18.6-alpined3e1620b530c
openssl@3.5.7-r0
3.5.8-r0
pgautoupgrade/pgautoupgrade:18-alpine48b448825656
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

32,151
devtron-operatordevtron0.23.36 of 11See more

devtron-operator devtron 0.23.3

6 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
openssl@3.5.7-r0
3.5.8-r0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

33,352
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

3,728
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

5,455
hcloud-csihcloud2.23.01 of 6See more

hcloud-csi hcloud 2.23.0

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,689
envoy-gatewayhelmforgeVerified publisher2.1.02 of 3See more

envoy-gateway helmforge 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
helmforge/kubectl:1.35.3c3f97e954c47
openssl@3.5.5-r0
3.5.8-r0
mccutchen/go-httpbin:v2.15.024528cf5229d
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

2,444
n8nhelmforgeVerified publisher2.0.11 of 2See more

n8n helmforge 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
n8nio/n8n:2.39.5cfa04788a34a
openssl@3.5.7-r1
3.5.8-r0

Open the chart page →

810

Container images carrying it

3,507 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/nmshd/backbone-housekeeper:7.2.11c1dfe35447f
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nmshd/backbone-identity-deletion-jobs:7.2.1da69941fa6b8
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/nowakeai/kube-insight:v0.1.475849fe6548a
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/obolnetwork/remote-signer:v0.4.0534baa453d3d
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/observal/observal-web:1.13.1738acf65cba7
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-1714527ca5d2a9
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/frontend:0.0.0-2026-08-17c18f4a1bc90a
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/okteto/redis:0.0.0-2026-08-03:0.0.0-2026-08-1761a0169cf291
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/registry:0.0.0-2026-08-1769131511501f
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
openssl@3.0.14-1~deb12u2
no fix listed
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
openssl@3.0.20-1~deb12u1
no fix listed
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/openfaas/faas-netes:0.18.176cfe35401d25
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/openfaas/gateway:0.27.1382b15393116e
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/openfaas/gateway:0.27.14ee0eaecc490c
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/openfaasltd/jetstream-queue-worker:0.5.10e9245a0bca88
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/openfaasltd/kafka-connector:0.7.160e58eac0e2f7
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
openssl@3.5.0-r0
3.5.8-r0
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/openlit/openlit-operator:0.0.2457bb5ada68b
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
openssl@3.0.18-1~deb12u2
no fix listed
1
ghcr.io/openrelik/openrelik-server:latestce1132261523
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.