StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,263
of 17,803 indexed, latest versions
Container images
3,507
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,263 of 17,803 indexed charts deploy, on 3,507 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,308
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,176
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,263 by stars
ChartLatestAffected imagesRadar Score
marketplace-apiappscodeVerified publisher2026.9.111 of 1See more

marketplace-api appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,710
offline-license-serverappscodeVerified publisher2026.9.112 of 2See more

offline-license-server appscode 2026.9.11

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/maxmind-geoip:city-mmdb-latesta3236324c4e2
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/appscode/offline-license-server:v0.0.76e4b66308d8f6
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,692
operator-shard-managerappscodeVerified publisher2026.6.221 of 1See more

operator-shard-manager appscode 2026.6.22

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/operator-shard-manager:v0.0.64a16c6ccecb8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

425
outbox-syncerappscodeVerified publisher2026.9.111 of 1See more

outbox-syncer appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/outboxsyncer:v0.5.0150baab6115d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

346
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,566
pgoutboxappscodeVerified publisher2026.7.101 of 1See more

pgoutbox appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/pgoutbox:v0.0.4a96e06ec5e9f
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

843
platform-apiappscodeVerified publisher2026.9.113 of 3See more

platform-api appscode 2026.9.11

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
ghcr.io/appscode/maxmind-geoip:city-mmdb-latesta3236324c4e2
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

37,889
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

702
regcacheappscodeVerified publisher2026.9.111 of 1See more

regcache appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/registry:3.1.11be55279f18a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

658
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29

Open the chart page →

3,326
secrets-store-csi-driver-provider-virtual-secretsappscodeVerified publisher2026.8.141 of 1See more

secrets-store-csi-driver-provider-virtual-secrets appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/secrets-store-csi-driver-provider-virtual-secrets:v0.2.07afb394f9f97
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

553
service-backendappscodeVerified publisher2026.9.111 of 1See more

service-backend appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,344
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,197
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/service-provider:v0.0.2f6e481386d70
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,252
sidekickappscodeVerified publisher2026.7.101 of 1See more

sidekick appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/sidekick:v0.0.16d8d2a3c22ee7
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

286
storage-metrics-serverappscodeVerified publisher2026.7.81 of 1See more

storage-metrics-server appscode 2026.7.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/storage-metrics-server:v0.1.09cb4acb742a9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

560
taskqueueappscodeVerified publisher2026.2.161 of 1See more

taskqueue appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/taskqueue:v0.0.36877c958a3c6
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,091
tricksterappscodeVerified publisher2026.1.151 of 1See more

trickster appscode 2026.1.15

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/trickster:v2.0.0cdbbed831f28
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,227
voyager-gatewayappscodeVerified publisher2026.7.211 of 2See more

voyager-gateway appscode 2026.7.21

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/crd-manager:v0.3.0e67f14e5c853
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,373
websiteappscodeVerified publisher2026.9.111 of 1See more

website appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/website:v2026.9.1170d9d1b78d39
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

371
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
openssl@3.0.9-1
no fix listed

Open the chart page →

5,704
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

8,931
appwriteappwrite-helmVerified publisher1.3.22 of 8See more

appwrite appwrite-helm 1.3.2

2 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
appwrite/appwrite:1.9.01aaa70127114
openssl@3.5.5-r0
3.5.8-r0
clamav/clamav:1.0dd0d9cc746af
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

9,855
arcadearcadeVerified publisher1.10.12 of 10See more

arcade arcade 1.10.1

2 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0
library/redis:8-alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

991
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

7,607
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

7,697
argonix-apiargonix0.2.91 of 4See more

argonix-api argonix 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api-frontend:1.0.0a584153dfae5
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

4,999
arlas-aiasarlas-stackVerified publisher28.8.012 of 22See more

arlas-aias arlas-stack 28.8.0

12 of the 22 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
openssl@3.0.16-1~deb12u1
no fix listed
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
openssl@3.0.16-1~deb12u1
no fix listed
gisaia/arlas-wui:28.0.3b83b3e067173
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

41,099
arlas-uisarlas-stackVerified publisher28.8.03 of 4See more

arlas-uis arlas-stack 28.8.0

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
gisaia/arlas-wui:28.0.3b83b3e067173
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,960
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

23,461
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

3,703
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

22,754
assemblylineassemblylineVerified publisher7.4.206 of 12See more

assemblyline assemblyline 7.4.20

6 of the 12 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable20098127270065
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-rust:4.7.4.stable202be5e6a57427
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-socketio:4.7.4.stable202b88493b62f7
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui:4.7.4.stable20efa75509b854
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui-frontend:4.7.4.stable208f3de0b45727
openssl@3.5.7-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

12,862
dltkvassist-iot-data-integrity-verification0.2.03 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

185,703
dltflassist-iot-dlt-based-fl0.2.03 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

185,703
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

9,428
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

13,413
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

10,179
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

83,638
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

8,072
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

7,986
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

5,382
smartorchestratorassist-iot-smart-orchestrator4.0.05 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

5 of the 14 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssl@3.0.9-1
no fix listed
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

45,972
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5
bluenviron/mediamtx:latest-ffmpeg9d148b5f2990
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

72,862
account-monitorastria0.0.11 of 1See more

account-monitor astria 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,978
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.29
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

32,715
auctioneerastria0.0.21 of 1See more

auctioneer astria 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,227
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

3,309
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,203
evm-rollupastria4.1.02 of 2See more

evm-rollup astria 4.1.0

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.8-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

4,038

Container images carrying it

3,507 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/pbufio/registry:v0.4.177a36c035b4b
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/pocket-id/pocket-id:v2.14.001540977dcf4
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/pocket-id/pocket-id:v2.7.045bdeaf3fcd6
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
1
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
ghcr.io/processone/ejabberd:latest5aeb0faa39cf
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/prophetse7en/clonarr:latest9400d298b37a
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.4
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/recyclarr/recyclarr:8.7.26e69e009e1cd
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/robbeverhelst/preparr:latest9acc172942f3
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
openssl@3.0.9-1
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/saidsef/faas-reverse-geocoding:latestca510c40aeee
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/sairam0424/ratecap-core:latest2f6c7157fa8e
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/sairam0424/ratecap-sidecar:lateste7feca7ac7cc
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm10
1
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm10
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/sebadob/rauthy:0.35.2a73dbf58359f
openssl@3.0.20-1~deb12u1
no fix listed
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
openssl@3.5.5-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.