StackRadar

CVE-2026-54874

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,174
of 17,821 indexed, latest versions
Container images
3,448
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-54874 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,174 of 17,821 indexed charts deploy, on 3,448 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+113 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,310
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,125
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed21
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm619
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-613
OSV records
ALPINE-CVE-2026-54874DEBIAN-CVE-2026-54874UBUNTU-CVE-2026-54874AZL-97953ECHO-66d7-e273-5f0f
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,174 by stars
ChartLatestAffected imagesRadar Score
pageslavanya-pages1.0.02 of 3See more

pages lavanya-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

20,285
helm-pilotlbenicio-communityVerified publisher0.2.41 of 1See more

helm-pilot lbenicio-community 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
lbenicio/helm-pilot:0.2.54594a2632510
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

716
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

3,577
listmonklbenicio-communityVerified publisher0.1.01 of 1See more

listmonk lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
listmonk/listmonk:latestf535d59e1499
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

720
speedtestlbenicio-communityVerified publisher0.1.01 of 1See more

speedtest lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/d0ugal/internet-perf-exporter:v0.2.91f5c9a96fe52a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

307
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
lbenicio/stremio-web:latest732f9003de33
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,602
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

33,925
ld-relayld-relay3.11.11 of 1See more

ld-relay ld-relay 3.11.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
launchdarkly/ld-relay:8.21.08fc1437962a9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

209
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

4,297
mosquittoleprechaun-charts0.1.41 of 1See more

mosquitto leprechaun-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
openssl@3.0.9-1
no fix listed

Open the chart page →

4,094
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,084
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

4,677
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
openssl@3.0.15-1~deb12u1
no fix listed
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,471
amplinguamatics0.12.01 of 4See more

amp linguamatics 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,110
data-factorylinguamatics1.0.11 of 4See more

data-factory linguamatics 1.0.1

1 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,110
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

38,692
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.41 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

1 of the 5 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,999
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.0.0bf3903d54a46
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,143
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,170
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,560
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,006
liturgical-appliturgical0.9.01 of 1See more

liturgical-app liturgical 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

955
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29

Open the chart page →

10,844
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,562
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

20,285
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

12,185
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,488
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,672
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,395
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

1,988
mt-mcp-proxyloafoe0.3.01 of 2See more

mt-mcp-proxy loafoe 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/github/github-mcp-server:latest508a0857ec76
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

505
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

949
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

7,581
sonarrloeken-at-homeVerified publisher4.0.181 of 1See more

sonarr loeken-at-home 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
loeken/sonarr:4.0.18ad0528ab7ba0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

859
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

33,925
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

804
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

2,546
elasticvuelogic3579Verified publisher1.15.01 of 1See more

elasticvue logic3579 1.15.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
cars10/elasticvue:1.15.0efddf4fa0fd8
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,083
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
library/redis:6.2e7b96daa9a18
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,172
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,511
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

6,692
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

6,610
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

23,806
logtidelogtideVerified publisher2.1.143 of 4See more

logtide logtide 2.1.14

3 of the 4 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,968
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

5,932
allure_docker_servicelovemew67Verified publisher0.0.11 of 1See more

allure_docker_service lovemew67 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.27.00815040339a9
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

65,433
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,909
vulnerability-scaninglovemew67Verified publisher0.0.31 of 2See more

vulnerability-scaning lovemew67 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-54874.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.35.14154286c0209
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15

Open the chart page →

5,245

Container images carrying it

3,448 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

No deployed image carries CVE-2026-54874.

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.