StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,245
of 17,803 indexed, latest versions
Container images
3,486
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,245 of 17,803 indexed charts deploy, on 3,486 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,300
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,163
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,245 by stars
ChartLatestAffected imagesRadar Score
rekorsigstoreVerified publisher1.8.61 of 9See more

rekor sigstore 1.8.6

1 of the 9 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
curlimages/curldigest-pinned935d9100e9ba
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

5,373
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29

Open the chart page →

2,970
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.01 of 3See more

swo-k8s-collector solarwinds 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,384
thehivestrangebee-helmOfficialVerified publisher1.0.75 of 7See more

thehive strangebee-helm 1.0.7

5 of the 7 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
openssl@3.0.17-1~deb12u2
no fix listed
curlimages/curl:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.8-r0
strangebee/thehive:5.8.0-1a7f7b05fba24
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

16,242
truenas-csptruenas-cspVerified publisher1.2.41 of 11See more

truenas-csp truenas-csp 1.2.4

1 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/datamattsson/truenas-csp:v3.2.09e58f2127d85
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,918
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

14,320
agonesagones1.60.01 of 5See more

agones agones 1.60.0

1 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.49ccd82364762
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,116
photoprismandrenarchyVerified publisher8.15.01 of 1See more

photoprism andrenarchy 8.15.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
photoprism/photoprism:260728958642220223
openssl@3.5.5-1ubuntu3.2
3.5.5-1ubuntu3.4

Open the chart page →

8,948
kubedbappscodeVerified publisher2026.7.107 of 8See more

kubedb appscode 2026.7.10

7 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/appscode/petset:v0.1.093fa0daf603c
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/appscode/sidekick:v0.0.15d1036b07e348
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/kubedb/kubedb-autoscaler:v0.51.05d1182ac21f0
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-crd-manager:v0.21.09506a6cb98d1
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/kubedb/kubedb-webhook-server:v0.42.0f7dcade6523b
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

4,180
cloudflaredartur9010Verified publisher1.0.92 of 3See more

cloudflared artur9010 1.0.9

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

3,008
openvpn-asas-helm-chartOfficialVerified publisher0.2.11 of 1See more

openvpn-as as-helm-chart 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
openvpn/openvpn-as:latest2253c10ec652
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

2,746
bambooatlassian-data-centerVerified publisher2.0.151 of 2See more

bamboo atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,167
alb-controllerazure-application-gateway-for-containers1.12.11 of 3See more

alb-controller azure-application-gateway-for-containers 1.12.1

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
mcr.microsoft.com/application-lb/images/alb-controller-crds:1.12.14dcf198fcb7c
openssl@3.3.7-4.azl3
3.3.7-6

Open the chart page →

233
baserowbaserow-chartVerified publisher1.0.565 of 6See more

baserow baserow-chart 1.0.56

5 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
baserow/backend:2.3.37c00549b3a6f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
baserow/web-frontend:2.3.3566d24c7d9f5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
openssl@3.0.13-1~deb12u1
no fix listed
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
openssl@3.0.14-1~deb12u2
no fix listed
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

17,468
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
openssl@1.1.1f-1ubuntu2
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

53,171
pgadmincetic0.1.121 of 1See more

pgadmin cetic 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dpage/pgadmin4:latest2f4ce946ddf8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

398
freshrsschristianhuthVerified publisher2.17.31 of 1See more

freshrss christianhuth 2.17.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
freshrss/freshrss:1.30.0-alpinefcff0b573f2b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
headwind-mdmchristianhuthVerified publisher5.10.22 of 2See more

headwind-mdm christianhuth 5.10.2

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed
headwindmdm/hmdm:0.1.93550b4840840
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

5,956
kuttchristianhuthVerified publisher9.10.21 of 3See more

kutt christianhuth 9.10.2

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
kutt/kutt:v3.2.6fa3d24a89b04
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

456
cloudquerycloudquery39.0.41 of 1See more

cloudquery cloudquery 39.0.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/cloudquery/cloudquery:6.40.040b804fce7f9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

551
routercosmo-routerOfficialVerified publisher0.18.01 of 1See more

router cosmo-router 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,694
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
openssl@3.0.15-1~deb12u1
no fix listed
dolibarr/dolibarr:22.0.47ad88fc9b13c
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

9,258
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

14,180
seafiledatamateVerified publisher0.6.04 of 6See more

seafile datamate 0.6.0

4 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
openssl@3.0.13-1~deb12u1
no fix listed
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
openssl@3.0.13-1~deb12u1
no fix listed
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
openssl@3.0.13-1~deb12u1
no fix listed
datamate/seafile-professional:11.0.202dd66b722464
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29

Open the chart page →

27,465
dialdialOfficialVerified publisher7.2.02 of 4See more

dial dial 7.2.0

2 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
epam/ai-dial-chat-themes:0.19.131af7cf96ee1
openssl@3.5.7-r0
3.5.8-r0
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,196
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,639
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,767
flannelflannel0.28.92 of 2See more

flannel flannel 0.28.9

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/flannel-io/flannel-cni-plugin:v1.9.1-flannel39fccdf677e6e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

616
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
redocly/redoc:latest2e26bb660574
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,277
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

2,591
geonode-k8sgeonode-k8sVerified publisher2.0.06 of 10See more

geonode-k8s geonode-k8s 2.0.0

6 of the 10 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.29
geonode/geoserver_data:2.28.4-latest435cbc5f3f05
openssl@3.5.6-r0
3.5.8-r0
geopython/pycsw:3.0.0-beta284662ea6b78b
openssl@3.0.17-1~deb12u3
no fix listed
library/memcached:1.6.40cc523a19da58
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.4.03906b477e4b6
openssl@3.0.17-1~deb12u3
no fix listed
nginxinc/nginx-unprivileged:1.31.2-alpine3.236320020c7da8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

14,147
glpiglpi-conteiner0.1.03 of 3See more

glpi glpi-conteiner 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/mariadb:latestdd9b303aed4f
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/phpmyadmin:latest3a8a8d6b5289
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
vdiogov/glpi-conteiner:latest6945f84f0058
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

12,399
haproxy-ingresshaproxy-ingressVerified publisher0.16.11 of 1See more

haproxy-ingress haproxy-ingress 0.16.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
quay.io/jcmoraisjr/haproxy-ingress:v0.16.16fd744191ef6
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

794
dolibarrhelmforgeVerified publisher1.2.181 of 3See more

dolibarr helmforge 1.2.18

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dolibarr/dolibarr:24.0.069ec52e3b7ef
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

4,204
karakeephelmforgeVerified publisher1.2.93 of 3See more

karakeep helmforge 1.2.9

3 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
getmeili/meilisearch:v1.53.0a59e984fd90b
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,553
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,689
postgresqlhelmforgeVerified publisher2.0.51 of 1See more

postgresql helmforge 2.0.5

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,667
umamihelmforgeVerified publisher2.3.32 of 3See more

umami helmforge 2.3.3

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,068
openctihelm-openctiVerified publisher3.0.103 of 8See more

opencti helm-opencti 3.0.10

3 of the 8 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
openssl@3.0.16-1~deb12u1
no fix listed
opencti/platform:7.260914.074f1242e6fa4
openssl@3.5.7-r0
3.5.8-r0
rustfs/rustfs:1.0.0-beta.1241fe89380f41
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,413
hertzbeathertzbeatOfficialVerified publisher1.8.13 of 4See more

hertzbeat hertzbeat 1.8.1

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
apache/hertzbeat-collector:1.8.0a2bab1be574c
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
library/postgres:159b1d34adbce1
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

14,314
infrahubinfrahubVerified publisher4.33.24 of 5See more

infrahub infrahub 4.33.2

4 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
openssl@3.0.15-1~deb12u1
no fix listed
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
openssl@3.0.17-1~deb12u2
no fix listed
library/neo4j:2026.05.06c162e2432f8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

10,561
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15

Open the chart page →

1,738
mosquittok8sonlabVerified publisher2.7.31 of 1See more

mosquitto k8sonlab 2.7.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.1.2-alpine6f8d8a947c50
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

187
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

6,370
kerberneteskerbernetesVerified publisher1.1.111 of 1See more

kerbernetes kerbernetes 1.1.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/froz42/kerbernetes:v1.1.6d5c074be8366
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
klusterviewklusterviewVerified publisher0.1.01 of 4See more

klusterview klusterview 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,812
kubeflowkubeflow1.6.24 of 45See more

kubeflow kubeflow 1.6.2

4 of the 45 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
istio/proxyv2:1.14.1df69c1a7af7c
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm5
library/python:3.7eedf63967cdb
openssl@3.0.9-1
no fix listed
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
openssl@1.0.2g-1ubuntu4.20
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

97,283
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

10,583
testkubekubeshop2.13.25 of 5See more

testkube kubeshop 2.13.2

5 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
kubeshop/testkube-api-server:2.13.244166c28422f
openssl@3.5.7-r0
3.5.8-r0
kubeshop/testkube-minio:2025.10d8e1af6aca99
openssl@3.0.20-1~deb12u2
no fix listed
library/nats:2.14.5-alpined4ac35882ac6
openssl@3.5.7-r0
3.5.8-r0
natsio/nats-server-config-reloader:0.24.0d758a82a9c20
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,178
sbomscannerkubewardenVerified publisher0.12.12 of 5See more

sbomscanner kubewarden 0.12.1

2 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/nats:2.14.6-alpinead7a43eb7e33
openssl@3.5.7-r0
3.5.8-r0
natsio/nats-server-config-reloader:0.23.064cb6c858e79
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,012

Container images carrying it

3,486 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/groundcovercom/kong/kubernetes-ingress-controller:3.5.3-20260205bf9db911deed
openssl@3.5.4-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
openssl@3.5.4-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
1
public.ecr.aws/groundcovercom/temporalio/server:1.29.6-mini-20260702-170f191d0a80e
openssl@3.5.6-1~deb13u1+e1
3.5.7-1~deb13u2
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssl@3.0.14-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
openssl@3.0.14-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
openssl@3.0.19-1~deb12u2
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
openssl@3.0.15-1~deb12u1
no fix listed
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
openssl@3.0.15-1~deb12u1
no fix listed
1
public.ecr.aws/opslevel/kubectl-opslevel:v2024.9.571697b5ff713
openssl@3.0.14-1~deb12u2
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
openssl@3.0.15-1~deb12u1
no fix listed
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssl@1.1.1f-1ubuntu2.3
1.1.1f-1ubuntu2.24+esm5
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssl@3.0.11-1~deb12u2
no fix listed
1
public.ecr.aws/truefoundrycloud/timberio/vector:v0.50.05833723de9e4
openssl@3.5.4-r0
3.5.8-r0
1
public.ecr.aws/zinclabs/openobserve:v0.8.127f8de509169
openssl@3.0.11-1~deb12u2
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
openssl@3.5.6-r0
3.5.8-r0
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
openssl@3.0.2-0ubuntu1.13
3.0.2-0ubuntu1.29
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
quay.io/cilium/hubble-ui:v0.13.3661d5de70501
openssl@3.5.2-r0
3.5.8-r0
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
openssl@3.0.15-1~deb12u1
no fix listed
1
quay.io/codefresh/dind:3.0.250885ab519dac
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
openssl@3.0.17-1~deb12u2
no fix listed
1
quay.io/cortexproject/cortex:v1.21.18577eb292a01
openssl@3.5.6-r0
3.5.8-r0
1
quay.io/datamattsson/truenas-csp:v3.2.09e58f2127d85
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
openssl@3.5.4-r0
3.5.8-r0
1
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
openssl@3.5.4-r0
3.5.8-r0
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.29
1
quay.io/enix/zfs-exporter:2.3.1223b053f1cbd0
openssl@3.5.6-r0
3.5.8-r0
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29
1
quay.io/fiware/vcverifier:6.21.251ed1e979094
openssl@3.5.7-r0
3.5.8-r0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
quay.io/groundcover/tools:20260719b705e0cbe171
openssl@3.5.6-1~deb13u2+e1
3.5.7-1~deb13u2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.