CVE-2026-63072
HighAdvisory
Published 25 Aug 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 50th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,294
- of 17,787 indexed, latest versions
- Container images
- 3,545
- deployed by those charts
- Fix available
- 4 of 5
- affected packages
CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6
Carried by container images the latest versions of 3,294 of 17,787 indexed charts deploy, on 3,545 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more | 1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more | 2,327 |
| opensslapk | 3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more | 3.5.8-r0 | 1,195 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 more | no fix listed | 16 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more | 1.0.2n-1ubuntu5.13+esm6 | 15 |
| opensslrpm | 3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl3 | 3.3.7-6 | 23 |
- OSV records
- ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
- Also known as
- USN-8678-1, USN-8678-2
Charts affected
3,294 by stars
Container images carrying it
3,545 by charts deploying them
A fixed version is listed for 4 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bitnamilegacy/ | 3ba6e6f11388 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 687034f33da6 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 85198aae0aed | openssl | no fix listed | 1 |
| bitnamilegacy/ | 90fda44bfa42 | openssl | no fix listed | 1 |
| bitnamilegacy/ | cc55da2fa366 | openssl | no fix listed | 1 |
| bitnamilegacy/ | cf63048c9209 | openssl | no fix listed | 1 |
| bitnamilegacy/ | d885ac277163 | openssl | no fix listed | 1 |
| bitnamilegacy/ | e6fa49bb0347 | openssl | no fix listed | 1 |
| bitnamilegacy/ | ea55532b6f75 | openssl | no fix listed | 1 |
| bitnamilegacy/ | fb3806e823c2 | openssl | no fix listed | 1 |
| bitnamilegacy/ | fdc6979dbc53 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 08b1b7cb6a5b | openssl | no fix listed | 1 |
| bitnamilegacy/ | 74a3d7c747eb | openssl | no fix listed | 1 |
| bitnamilegacy/ | cd593809e359 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 189aae381e7f | openssl | no fix listed | 1 |
| bitnamilegacy/ | 5261cae9e407 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 6a5b1d0b5942 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 70cafc5a71e8 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 9c6fecd24bf3 | openssl | no fix listed | 1 |
| bitnamilegacy/ | cdc2efa9c306 | openssl | no fix listed | 1 |
| bitnamilegacy/ | a53d023fdfaf | openssl | no fix listed | 1 |
| bitnamilegacy/ | a006df1fd47e | openssl | no fix listed | 1 |
| bitnamilegacy/ | 0ca3ea1d2f82 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 0cb31d0fc356 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 0384ca2eec63 | openssl | no fix listed | 1 |
| bitnamilegacy/ | 4f0191fba7d3 | openssl | no fix listed | 1 |
| bitnamilegacy/ | a185655855b3 | openssl | no fix listed | 1 |
| bitnami/ | 16a7dae804fb | openssl | no fix listed | 1 |
| bitnami/ | dd8f2cba9a5b | openssl | no fix listed | 1 |
| bitnami/ | b3bd5b6be9a0 | openssl | no fix listed | 1 |
| bitnami/ | 4e65bf641805 | openssl | no fix listed | 1 |
| blackducksoftware/ | c14bbbf45536 | openssl | 3.5.7-1~deb13u2 | 1 |
| blackducksoftware/ | b10eaea94fd3 | openssl | 3.5.7-1~deb13u2 | 1 |
| blackducksoftware/ | 90cca32de2cc | openssl | 3.5.8-r0 | 1 |
| blackducksoftware/ | 6310fac39d53 | openssl | 3.5.8-r0 | 1 |
| blackducksoftware/ | 8f422b18d171 | openssl | 3.5.8-r0 | 1 |
| blakeblackshear/ | ae269270ad9e | openssl | 1.1.1f-1ubuntu2.24+esm5 | 1 |
| blockstream/ | 9472492530e3 | openssl | no fix listed | 1 |
| bloxstaking/ | bf6d7d2fdc93 | openssl | no fix listed | 1 |
| bluenviron/ | 9d148b5f2990 | openssl | 3.5.8-r0 | 1 |
| bmeares/ | 8e9c5bacaa82 | openssl | no fix listed | 1 |
| bnjbvr/ | 37e216b182c8 | openssl | no fix listed | 1 |
| boky/ | aafc77238423 | openssl | 3.5.7-1~deb13u2 | 1 |
| boky/ | f3f247fd4252 | openssl | no fix listed | 1 |
| bolkedebruin/ | c0dc0589373a | openssl | 3.5.8-r0 | 1 |
| boxcutter/ | 84e13f01bcab | openssl | 3.0.2-0ubuntu1.29 | 1 |
| browserless/ | c81ae5585b47 | openssl | 1.1.1f-1ubuntu2.24+esm5 | 1 |
| budibase/ | 44fe6feab985 | openssl | 3.5.8-r0 | 1 |
| budibase/ | d90f656261c9 | openssl | no fix listed | 1 |
| budibase/ | 8d780b6ee602 | openssl | 3.5.7-1~deb13u2 | 1 |