StackRadar

CVE-2026-63072

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,470
of 17,803 indexed, latest versions
Container images
3,788
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,470 of 17,803 indexed charts deploy, on 3,788 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,308
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,457
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm615
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,470 by stars
ChartLatestAffected imagesRadar Score
registrywiremindVerified publisher0.1.11 of 1See more

registry wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/distribution/distribution:3.0.04ba3adf47f5c
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,357
silence-operatorwiremindVerified publisher0.0.81 of 1See more

silence-operator wiremind 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
giantswarm/silence-operator:0.13.0a6cac55aa2d4
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

934
wordpress-alpinewordpress-alpine1.5.183 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

3 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/mariadb:12.3.2628f228f0fd5
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
library/memcached:1.6.45dc561d52bb8a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/shesselink81/nginx-alpine:7.1.0.09783481cad2a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,103
Wordpresswordpress-mariadb1.0.22 of 2See more

Wordpress wordpress-mariadb 1.0.2

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/mariadb:ltsdd9b303aed4f
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/wordpress:latest5a93c470ae82
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,737
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
openssl@3.0.2-0ubuntu1.16
no fix listed
3.0.2-0ubuntu1.29

Open the chart page →

14,226
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

11,643
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

7,672
xkopsxkops0.1.04 of 5See more

xkops xkops 0.1.0

4 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
openssl@3.0.14-1~deb12u2
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
openssl@3.0.14-1~deb12u2
no fix listed
library/mongo:latest5211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
murtazashah46/helmfile:latest4d11726cf803
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

13,875
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.15

Open the chart page →

2,156
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

1,330
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

936
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,710
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

2,477
changedetection-iozekker6Verified publisher1.101.01 of 1See more

changedetection-io zekker6 1.101.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,649
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

490
homerzekker6Verified publisher8.35.01 of 1See more

homer zekker6 8.35.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
b4bz/homer:v26.08.3febc8967c9f7
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
language-toolzekker6Verified publisher1.12.12 of 2See more

language-tool zekker6 1.12.1

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
openssl@3.5.5-r0
3.5.8-r0
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,569
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,160
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm10
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

9,280
zoo-project-druzoo-projectOfficialVerified publisher0.10.44 of 6See more

zoo-project-dru zoo-project 0.10.4

4 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
curlimages/curl:8.21.07c12af72ceb3
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.4-alpine3.249a8afca54e78
openssl@3.5.7-r0
3.5.8-r0
library/rabbitmq:4.3.2-alpine835cbc6fabce
openssl@3.5.7-r0
3.5.8-r0
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

7,949

Container images carrying it

3,788 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
akeyless/base:latest759e4289fae8
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15
1
akeyless/k8s-webhook-server:0.39.0996cd9afb3b4
openssl@3.5.7-r0
3.5.8-r0
1
aktosecurity/akto-agent-guard-anonymizer:1.1.4d4b100cbdc47
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
aktosecurity/akto-agent-guard-embedder:1.1.4dbc566b2376c
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
aktosecurity/akto-agent-guard-worker:1.1.4666eaffd5362
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
aktosecurity/akto-api-security-dashboard:latest3aeaee66bc66
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
openssl@3.5.1-r0
3.5.8-r0
1
aktosecurity/akto-threat-detection-backend:1.15.7a6c1b933517f
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
aktosecurity/data-ingestion-service213aded7adc5
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
openssl@3.5.5-1ubuntu3.2
3.5.5-1ubuntu3.4
1
aktosecurity/data-ingestion-service:1.5.35d4eab1c36b9
openssl@3.5.5-1ubuntu3.2
3.5.5-1ubuntu3.4
1
aktosecurity/mini-runtime:1.72.15498e3e35ecc2
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
1
aktosecurity/mirror-api-logging:k8s_agentc1313b1ff2ed
openssl@3.5.7-r0
3.5.8-r0
1
aktosecurity/mirror-api-logging:k8s_ebpffcf8be10bead
openssl@3.5.7-r0
3.5.8-r0
1
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.8-r0
1
alazidis/stornx:1.1.1602d4f7f090c
openssl@3.0.18-1~deb12u2
no fix listed
1
alireza7/s-ui:1.5.302aa86983cdb
openssl@3.5.7-r0
3.5.8-r0
1
allegroai/clearml:2.0.0-613713ae38f7daf
openssl@3.0.15-1~deb12u1
no fix listed
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
openssl@1.1.1-1ubuntu2.1~18.04.19
openssl1.0@1.0.2n-1ubuntu5.10
1.1.1-1ubuntu2.1~18.04.23+esm10
1.0.2n-1ubuntu5.13+esm6
1
alpine/curl:8.12.08943e8c7e8e4
openssl@3.3.2-r4
3.3.7-r1
1
alpine/curl:8.21.0a1c44bab54d8
openssl@3.5.7-r0
3.5.8-r0
1
alpine/git:v2.49.1c0280cf95723
openssl@3.5.4-r0
3.5.8-r0
1
alpine/helm:4.1.0905a068da431
openssl@3.5.4-r0
3.5.8-r0
1
alpine/k8s:1.36.244ef4942e171
openssl@3.5.5-r0
3.5.8-r0
1
alpine/k8s:1.31.106dbe6f391eda
openssl@3.5.0-r0
3.5.8-r0
1
alpine/k8s:1.31.137a319b15cfc9
openssl@3.5.1-r0
3.5.8-r0
1
alpine/k8s:1.32.47e1e7d5b7a96
openssl@3.3.3-r0
3.3.7-r1
1
alpine/k8s:1.31.49c4976d47656
openssl@3.3.2-r4
3.3.7-r1
1
alpine/k8s:1.35.6b7a12c5ddf26
openssl@3.5.5-r0
3.5.8-r0
1
alpine/k8s:1.35.5d870622d0040
openssl@3.5.5-r0
3.5.8-r0
1
alpine/k8s:1.32.3eec354133193
openssl@3.3.3-r0
3.3.7-r1
1
alpine/kubectl:1.36.01ee9df6316d4
openssl@3.5.6-r0
3.5.8-r0
1
alpine/kubectl:1.33.32c59a3f0726c
openssl@3.5.1-r0
3.5.8-r0
1
alpine/kubectl:1.35.0862d86046bbc
openssl@3.5.5-r0
3.5.8-r0
1
alpine/kubectl:1.35.3c4a11ae9a1cb
openssl@3.5.5-r0
3.5.8-r0
1
alpine/psql:18.339824ef2b7fc
openssl@3.5.6-r0
3.5.8-r0
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
openssl@3.3.3-r0
3.3.7-r1
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
openssl@3.3.3-r0
3.3.7-r1
1
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
1
anguda/ant-media:2.5c435285fc241
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
openssl@3.0.11-1~deb12u1
no fix listed
1
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
antrea/flow-aggregator:v2.7.0065193e7572f
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
anujdatar/cups:25.07.01685df04a643b
openssl@3.0.16-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.