StackRadar

CVE-2026-63072

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,268
of 17,787 indexed, latest versions
Container images
3,501
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,268 of 17,787 indexed charts deploy, on 3,501 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,302
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,176
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,268 by stars
ChartLatestAffected imagesRadar Score
feedbacksystemthm-mni-iiVerified publisher0.47.14 of 10See more

feedbacksystem thm-mni-ii 0.47.1

4 of the 10 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
openssl@3.5.1-r0
3.5.8-r0
thmmniii/fbs-core:v1.27.15438517d9fc2
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
openssl@3.5.1-r0
3.5.8-r0
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

28,534
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

10,315
crossplaneupbound-stable2.4.0-up.11 of 5See more

crossplane upbound-stable 2.4.0-up.1

1 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,626
uptraceuptrace2.0.21 of 2See more

uptrace uptrace 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
uptrace/uptrace:2.0.234a02c3b2d12
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,619
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
openssl@1.1.1-1ubuntu2.1~18.04.8
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

18,137
vaultvaultVerified publisher1.22.03 of 4See more

vault vault 1.22.0

3 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
alpine/k8s:1.35.5d870622d0040
openssl@3.5.5-r0
3.5.8-r0
hashicorp/vault:2.0.1755355002715
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/bank-vaults/bank-vaults:v1.33.198b6ea2ed319
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

4,243
victoria-metrics-authvictoriametricsVerified publisher0.41.01 of 1See more

victoria-metrics-auth victoriametrics 0.41.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
victoriametrics/vmauth:v1.151.0efd05bb90de9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

4,378
prometheus-mikrotik-exportervrs-factoryVerified publisher0.6.11 of 2See more

prometheus-mikrotik-exporter vrs-factory 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/akpw/mktxp:1.2.20f894f2457670
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

182
api-firewallwallarmVerified publisher0.9.61 of 1See more

api-firewall wallarm 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
wallarm/api-firewall:v0.9.64d45db0ff240
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

999
argo-cdwenerme10.9.12See more

argo-cd wenerme 10.9.1

2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ecr-public.aws.com/docker/library/redis:8.6.4-alpine2cc044fc5a07
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/dexidp/dex:v2.45.18499afd690c4
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

wgerwgerOfficialVerified publisher1.0.05 of 8See more

wger wger 1.0.0

5 of the 8 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/postgres:15.186eb0add3b77c
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.8.0234c902a2db4
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
wger/server:2.6997ead43aabd
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15

Open the chart page →

8,491
windmillwindmill4.0.2631See more

windmill windmill 4.0.263

1 container image this version deploys carries CVE-2026-63072.

Container imageDigestPackageFixed in
library/postgres:184ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

buildkitdwiremindVerified publisher0.33.01 of 1See more

buildkitd wiremind 0.33.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
moby/buildkit:v0.32.2-rootless504731e577c2
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,152
zeroclawzeroclawVerified publisher0.2.11 of 2See more

zeroclaw zeroclaw 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

778
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,044
adguardhomeadguardhome0.1.271 of 1See more

adguardhome adguardhome 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.79aba9e3bf0613
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

175
paperless-ngxadnoctemVerified publisher0.4.22 of 5See more

paperless-ngx adnoctem 0.4.2

2 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29
gotenberg/gotenberg:8.36.087c16b9f3642
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

19,691
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

13,635
aerospike-graphaerospike-helmOfficialVerified publisher3.7.01 of 1See more

aerospike-graph aerospike-helm 3.7.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
aerospike/aerospike-graph-service:3.3.1781ba5213efd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

322
agentareaagentareaVerified publisher0.0.189 of 16See more

agentarea agentarea 0.0.18

9 of the 16 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
agentarea/agentarea-api:latest9e15e16fa758
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
agentarea/agentarea-frontend:latest2098a9d7b1fe
openssl@3.5.7-r0
3.5.8-r0
agentarea/agentarea-mcp-runner:latestd3c209a5d531
openssl@3.0.20-1~deb12u2
no fix listed
agentarea/agentarea-worker:latest1e5cb68ee77a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/postgres:16-alpinecf78e76683b9
openssl@3.5.7-r0
3.5.8-r0
library/postgres:alpined3e1620b530c
openssl@3.5.7-r0
3.5.8-r0
rustfs/rustfs:latest41fe89380f41
openssl@3.5.7-r0
3.5.8-r0
temporalio/auto-setup:1.29.15b3502a3b685
openssl@3.5.0-r0
3.5.8-r0
valkey/valkey:9.0.1546304417fea
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

14,914
akeyless-api-gatewayakeyless-services-helmVerified publisher1.62.221 of 1See more

akeyless-api-gateway akeyless-services-helm 1.62.22

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
akeyless/base:latest759e4289fae8
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15

Open the chart page →

2,358
icat-k8salba-helm-chartsVerified publisher1.1.02 of 4See more

icat-k8s alba-helm-charts 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
curlimages/curl:8.18.0d94d07ba9e7d
openssl@3.5.4-r0
3.5.8-r0
payara/server-full:7.2026.2-jdk2531f1253f0cf8
openssl@3.0.2-0ubuntu1.21
3.0.2-0ubuntu1.29

Open the chart page →

3,697
adguard-homealekcVerified publisher3.2.01 of 2See more

adguard-home alekc 3.2.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.79aba9e3bf0613
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

175
ddclientalekcVerified publisher1.1.01 of 1See more

ddclient alekc 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
linuxserver/ddclient:4.0.06468911d00b1
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

360
jellyfinalekcVerified publisher0.9.01 of 1See more

jellyfin alekc 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,604
alertmanager-receiver-azdoalertmanager-receiver-azdoVerified publisher1.0.1081 of 1See more

alertmanager-receiver-azdo alertmanager-receiver-azdo 1.0.108

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/ivanjosipovic/alertmanager-receiver-azdo/alertmanager-receiver-azdo:1.0.108731943808ee7
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.02 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

12,037
clearml-agentallegroaiVerified publisher5.3.31 of 1See more

clearml-agent allegroai 5.3.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
openssl@1.1.1-1ubuntu2.1~18.04.19
openssl1.0@1.0.2n-1ubuntu5.10
1.1.1-1ubuntu2.1~18.04.23+esm10
1.0.2n-1ubuntu5.13+esm6

Open the chart page →

12,046
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

8,341
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,880
upcloud-csiankra-chartsVerified publisher0.4.02 of 8See more

upcloud-csi ankra-charts 0.4.0

2 of the 8 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
openssl@3.5.1-r0
3.5.8-r0
ghcr.io/upcloudltd/upcloud-csidigest-pinned5af91c663788
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

14,917
alazanteonVerified publisher0.12.01 of 1See more

alaz anteon 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ddosify/alaz:v0.12.0ea602056d9ce
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

3,366
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
openssl@3.0.11-1~deb12u2
no fix listed
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

22,202
antreaantreaVerified publisher2.7.02 of 2See more

antrea antrea 2.7.0

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

3,231
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29

Open the chart page →

7,740
kubedb-provisionerappscodeVerified publisher0.66.01 of 1See more

kubedb-provisioner appscode 0.66.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

500
scannerappscodeVerified publisher2026.1.152 of 3See more

scanner appscode 2026.1.15

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/appscode/scanner:v0.0.2116907aae5de1
openssl@3.5.4-r0
3.5.8-r0
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

5,299
virtual-secrets-serverappscodeVerified publisher2026.8.141 of 1See more

virtual-secrets-server appscode 2026.8.14

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/appscode/virtual-secrets-server:v0.4.0efa03f4c9551
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

280
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

5,222
arvancloud-webhookarvancloud-webhookVerified publisher1.0.01 of 1See more

arvancloud-webhook arvancloud-webhook 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,297
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

17,896
dltbrokerassist-iot-distributed-broker0.2.03 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.03 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

77,687
astradnsastradnsVerified publisher0.2.91 of 2See more

astradns astradns 0.2.9

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
openssl@3.0.18-1~deb12u2
no fix listed

Open the chart page →

2,613
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

4,292
kube-image-webhookav1o-chartsVerified publisher0.1.31 of 1See more

kube-image-webhook av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

3,723
kinesisaws-kinesis-local0.8.01 of 1See more

kinesis aws-kinesis-local 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
saidsef/aws-kinesis-local:v2026.0667025e3a163e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

360
azuredisk-csi-driverazuredisk-csi-driverVerified publisher1.34.57 of 8See more

azuredisk-csi-driver azuredisk-csi-driver 1.34.5

7 of the 8 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.34.552b33e858369
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-attacher:v4.12.016987358befc
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0b767078c36e0
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.09915a2058ad6
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.04bfe19fe8919
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.6.0557008207ca4
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.0bd19535678a8
openssl@3.3.7-4.azl3
3.3.7-6

Open the chart page →

794
vault-unsealbabykart-helm-chartsVerified publisher1.0.51 of 1See more

vault-unseal babykart-helm-charts 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/lrstanley/vault-unseal:1.0.1dd873930b6df
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

205

Container images carrying it

3,501 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
openssl@3.0.20-1~deb12u2
no fix listed
2
ghcr.io/mogenius/mo-backup:latest4f89afef9010
openssl@3.5.7-r0
3.5.8-r0
2
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
openssl@3.0.14-1~deb12u2
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
openssl@3.0.16-1~deb12u1
no fix listed
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
openssl@3.5.0-r0
3.5.8-r0
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
openssl@3.0.16-1~deb12u1
no fix listed
2
ghcr.io/opencost/opencost:1.121.2de2784434527
openssl@3.5.7-r0
3.5.8-r0
2
ghcr.io/plausible/community-edition:v3.2.133e60bfb40f2
openssl@3.5.6-r0
3.5.8-r0
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
openssl@3.0.11-1~deb12u2
no fix listed
2
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
openssl@3.0.15-1~deb12u1
no fix listed
2
ghcr.io/salaboy/fmtok8s-agenda-service:v0.0.1-native6c5efe150958
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm10
2
ghcr.io/salaboy/fmtok8s-c4p-service:v0.0.1-native3f7cc45fd20b
openssl@1.1.1-1ubuntu2.1~18.04.21
1.1.1-1ubuntu2.1~18.04.23+esm10
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
openssl@3.0.2-0ubuntu1.2
3.0.2-0ubuntu1.29
2
ghcr.io/smarter-project/home-ha-mock:main95ee018cf558
openssl@3.0.15-1~deb12u1
no fix listed
2
ghcr.io/smarter-project/hydra/isolated-vm:main4457b79b24cd
openssl@3.0.18-1~deb12u2
no fix listed
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
openssl@3.5.7-r0
3.5.8-r0
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
openssl@3.5.0-r0
3.5.8-r0
2
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm5
2
public.ecr.aws/aktosecurity/akto-api-security-dashboard:1.69.2:latestb53a854bd7c1
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
2
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.7-1~deb13u2
2
public.ecr.aws/gravitational/tbot-distroless:18.11.04ba5ace31fea
openssl@3.0.20-1~deb12u2
no fix listed
2
public.ecr.aws/truefoundrycloud/timberio/vector:v0.52.088b8dc80ae74
openssl@3.5.6-r0
3.5.8-r0
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
2
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
openssl@3.5.7-r0
3.5.8-r0
2
quay.io/cilium/cilium-envoy:v1.37.5-1786810558-766ccfb37260a43e9d228837aa84ce3faf9f64e775b8094c7127
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
2
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
openssl@3.5.7-r0
3.5.8-r0
2
quay.io/curl/curl:8.16.0b17b13321678
openssl@3.5.2-r0
3.5.8-r0
2
quay.io/frrouting/frr:10.4.38745af1f9bbb
openssl@3.5.5-r0
3.5.8-r0
2
quay.io/jcmoraisjr/haproxy-ingress:v0.16.16fd744191ef6
openssl@3.5.6-r0
3.5.8-r0
2
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.8-r0
2
quay.io/metallb/frr-k8s:v0.0.251cb06fb2d553
openssl@3.5.6-r0
3.5.8-r0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
openssl@3.5.4-r0
3.5.8-r0
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
openssl@3.5.5-r0
3.5.8-r0
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
openssl@3.5.0-r0
3.5.8-r0
2
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
openssl@3.0.20-1~deb12u2
no fix listed
2
1dev/server:11.9.0cd5b12fe5471
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
1password/connect-api:1.8.2e915c0c84397
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
1password/connect-sync:1.8.26297ca6136c0
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
2martens/timetable:latestbd1ba6ab84c9
openssl@3.5.1-r0
3.5.8-r0
1
2martens/wahlrecht:latestba2c3040dab0
openssl@3.5.1-r0
3.5.8-r0
1
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
openssl@3.0.9-1
no fix listed
1
5200710/hadoop:3.2.3-java8092d3088a5fb
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
1
a10networks/acos-prometheus-exporter:latest8dc58d434d71
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm10
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
1
aaronshaf/dynamodb-admin:latestac41724cd997
openssl@3.5.6-r0
3.5.8-r0
1
aboogie/login_test_backend:new9c41a4483ac8
openssl@3.0.13-1~deb12u1
no fix listed
1
adguard/adguardhome:v0.107.767157eb1dc3b2
openssl@3.5.6-r0
3.5.8-r0
1
adguard/adguardhome:v0.107.737fbf01d73ecb
openssl@3.5.5-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.