StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,269
of 17,805 indexed, latest versions
Container images
3,470
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,269 of 17,805 indexed charts deploy, on 3,470 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,292
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,158
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-620
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,269 by stars
ChartLatestAffected imagesRadar Score
csi-driver-smbdeimosfr-charts1.20.31 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

1 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

3,019
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

6,128
technitiumdeimosfr-charts15.4.01 of 1See more

technitium deimosfr-charts 15.4.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

1,365
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,351
dell-fan-controllerdell-fan-controllerVerified publisher1.0.71 of 1See more

dell-fan-controller dell-fan-controller 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

2,578
challengedeneme0.1.02 of 2See more

challenge deneme 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:6143f7bfc2358
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,783
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
openssl@1.1.1f-1ubuntu2.18
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

7,283
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

8,179
deployhubdeployhubVerified publisher10.0.4152 of 11See more

deployhub deployhub 10.0.415

2 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
openssl@3.5.4-r0
3.5.8-r0
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

11,241
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

72,223
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,533
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,267
frontend-servicedev-krishan-dhaka-charts1.0.21 of 1See more

frontend-service dev-krishan-dhaka-charts 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
devkrishan001/frontend:latesta0ad60836e6b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,032
postgresdev-krishan-dhaka-charts1.0.21 of 1See more

postgres dev-krishan-dhaka-charts 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

494
devnopesdevnopes0.1.81 of 1See more

devnopes devnopes 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
sokushinbutsu/devnopes:latest0bbd90448671
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

462
apachedevops0.1.03 of 4See more

apache devops 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.29

Open the chart page →

111,395
laraveldevops0.10.33 of 4See more

laravel devops 0.10.3

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mariadb:10.9.4fbb8456ebdb1
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
openssl@3.0.2-0ubuntu1.6
no fix listed
3.0.2-0ubuntu1.29

Open the chart page →

110,396
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

13,054
devops-diplomdevops-diplom-chartVerified publisher0.8.01 of 2See more

devops-diplom devops-diplom-chart 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:13-alpinefb9065b6e3e2
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,550
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

9,743
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

13,159
caddy-reverse-proxydevtron0.10.11 of 1See more

caddy-reverse-proxy devtron 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/caddy:latest13ba145cba2f
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

863
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

4,704
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/dashboard:0d8f6cf4-60e17132-931-39393aa61fffb8ae8
openssl@3.5.7-r0
3.5.8-r0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm18
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

69,552
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29

Open the chart page →

4,983
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

11,990
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,947
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

9,743
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

13,159
caddy-reverse-proxydevtron-labs0.10.11 of 1See more

caddy-reverse-proxy devtron-labs 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/caddy:latestdf7f1c2fb114
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

863
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

4,704
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/dashboard:0d8f6cf4-60e17132-931-39393aa61fffb8ae8
openssl@3.5.7-r0
3.5.8-r0
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm18
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
openssl@3.0.17-1~deb12u3
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

69,552
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29

Open the chart page →

4,983
devtron-operatordevtron-labs0.23.36 of 11See more

devtron-operator devtron-labs 0.23.3

6 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/dashboard:c7b89667-690-39290c63823af3835
openssl@3.5.7-r0
3.5.8-r0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
openssl@3.0.11-1~deb12u2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
quay.io/devtron/postgres:14.91b594392f7cb
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

33,352
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

11,990
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

3,947
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.03 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm10
library/rabbitmq:3-managemente582c0bc7766
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
oscarsotosanchez/weatherservice:v1.0911ec961d10b
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

27,703
rateldgraph25.0.31 of 1See more

ratel dgraph 25.0.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dgraph/ratel:v25.0.34cae1ff95027
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,003
dial-admindialVerified publisher0.18.02 of 3See more

dial-admin dial 0.18.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
openssl@3.0.16-1~deb12u1
no fix listed
epam/ai-dial-admin-frontend:0.20.021d91ad74755
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,103
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
openssl@3.0.15-1~deb12u1
no fix listed
langgenius/dify-sandbox:0.2.009b7e8705673
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

47,013
pagesdipak1.0.02 of 3See more

pages dipak 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

20,261
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

7,570
alertifydjjudas21Verified publisher0.1.01 of 1See more

alertify djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
djjudas21/alertify:0.1.0ba22be670c37
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

2,421
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
openssl@3.0.9-1
no fix listed

Open the chart page →

7,342
ecowitt-exporterdjjudas21Verified publisher2.2.21 of 1See more

ecowitt-exporter djjudas21 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,006
liturgical-colourdjjudas21Verified publisher99.99.991 of 1See more

liturgical-colour djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
djjudas21/liturgical-colour-app:0.7.2954935971d42
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

873
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,412
ownclouddjjudas21Verified publisher0.3.233 of 3See more

owncloud djjudas21 0.3.23

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
openssl@3.0.13-1~deb12u1
no fix listed
owncloud/server:10.16.3b3f9efdcd7f7
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
valkey/valkey:8.1.481db6d39e1bb
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2

Open the chart page →

10,254
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.15

Open the chart page →

87,945
spoolmandjjudas21Verified publisher0.1.81 of 1See more

spoolman djjudas21 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.24.042135965c42d
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,877

Container images carrying it

3,470 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm5
1
mcr.microsoft.com/mssql/server:latest4bab24f36c1e
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
1.1.1-1ubuntu2.1~18.04.23+esm10
1.0.2n-1ubuntu5.13+esm6
1
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.8.2f21fca343428
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.76e43ba0bd009
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/blob-csi:v1.27.9f9e20264150a
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.14.06cb172e3de7e
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.16.0b5ff0d884b68
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v5.2.0afdfa3da79df
openssl@3.3.5-1.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v1.13.2fa8eba9843ff
openssl@3.3.5-3.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.5.08b3ce8339944
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
openssl@3.3.5-3.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
openssl@3.3.5-5.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
openssl@3.3.5-5.azl3
3.3.7-6
1
mcr.microsoft.com/oss/v2/nvidia/k8s-device-plugin:v0.18.2-125a4e52c87bb9
openssl@3.3.7-4.azl3
3.3.7-6
1
public.ecr.aws/aktosecurity/akto-ai-automated-testing:latest5a5d32281374
openssl@3.0.20-1~deb12u2
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:1.66.9138c8b82c398
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
public.ecr.aws/aktosecurity/akto-api-security-database-abstractor:latestf669a6eacf8c
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
1
public.ecr.aws/aktosecurity/akto-api-testing:latest97d830d5538a
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
openssl@3.5.6-r0
3.5.8-r0
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
openssl@3.5.5-r0
3.5.8-r0
1
public.ecr.aws/aktosecurity/redis47200b041382
openssl@3.0.17-1~deb12u3
no fix listed
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
openssl@3.5.1-r0
3.5.8-r0
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
1
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
1
public.ecr.aws/groundcovercom/kong:3.9.3-mini-20260804-107dfd0693fc4
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
openssl@3.5.4-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
openssl@3.5.4-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
openssl@3.5.6-1~deb13u1+e1
3.5.7-1~deb13u2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssl@3.0.14-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
openssl@3.0.14-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
openssl@3.0.19-1~deb12u2
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
openssl@3.0.15-1~deb12u1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
openssl@3.0.15-1~deb12u1
no fix listed
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
openssl@3.0.15-1~deb12u1
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.