CVE-2026-63072
HighAdvisory
Published 25 Aug 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 51st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3,513
- of 17,805 indexed, latest versions
- Container images
- 3,801
- deployed by those charts
- Fix available
- 4 of 5
- affected packages
CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6
Carried by container images the latest versions of 3,513 of 17,805 indexed charts deploy, on 3,801 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more | 1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more | 2,326 |
| opensslapk | 3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more | 3.3.7-r1, 3.5.8-r0 | 1,455 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 more | no fix listed | 22 |
| openssl1.0deb | 1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more | 1.0.2n-1ubuntu5.13+esm6 | 20 |
| opensslrpm | 3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl3 | 3.3.7-6 | 20 |
- OSV records
- ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
- Also known as
- USN-8678-1, USN-8678-2
Charts affected
3,513 by stars
Container images carrying it
3,801 by charts deploying them
A fixed version is listed for 4 of the 5 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| rancher/ | 946ae0d13229 | openssl | 3.5.8-r0 | 1 |
| rancher/ | 1eba82e9c386 | openssl | 3.5.8-r0 | 1 |
| rancher/ | 9289da488b07 | openssl | 3.5.8-r0 | 1 |
| rancher/ | e66f32d19eb9 | openssl | 1.0.2g-1ubuntu4.20+esm18 | 1 |
| rancher/ | 89c3f898ac5a | openssl | 3.5.8-r0 | 1 |
| razorbladex401/ | 6a4d79248e7d | openssl | 3.0.2-0ubuntu1.29 | 1 |
| rclone/ | 45401ad7410d | openssl | 3.5.8-r0 | 1 |
| readysettech/ | 588f3507280e | openssl | 3.0.13-0ubuntu3.15 | 1 |
| readysettech/ | 67a83203ce60 | openssl | 3.0.13-0ubuntu3.15 | 1 |
| reallibrephotos/ | 98a13dabbadc | openssl | 3.5.7-1~deb13u2 | 1 |
| reaper99/ | 7f7ec3aeb88c | openssl | 3.3.7-r1 | 1 |
| redash/ | 00d813437db5 | openssl | no fix listed | 1 |
| redash/ | c5c9148f5c38 | openssl | no fix listed | 1 |
| redimp/ | 778bf30da3da | openssl | no fix listed | 1 |
| redis/ | 55542a762210 | openssl | 3.3.7-r1 | 1 |
| redis/ | 85562d67a912 | openssl | 3.5.8-r0 | 1 |
| redis/ | 51a58f32d412 | openssl | 1.1.1f-1ubuntu2.24+esm5 | 1 |
| redis/ | 798ab84d9f26 | openssl | 3.0.2-0ubuntu1.29 | 1 |
| redis/ | 887cf87cc744 | openssl | 3.0.2-0ubuntu1.29 | 1 |
| redocly/ | 2e26bb660574 | openssl | 3.5.8-r0 | 1 |
| redpandadata/ | 56da99e8d0d3 | openssl | 3.5.8-r0 | 1 |
| redpandadata/ | c05fa976428e | openssl | 3.5.8-r0 | 1 |
| redpandadata/ | 468bd13a9f2b | openssl | 3.5.7-1~deb13u2 | 1 |
| reportportal/ | 06cdf299b397 | openssl | 3.5.8-r0 | 1 |
| reportportal/ | 464468240d7b | openssl | 3.5.8-r0 | 1 |
| reportportal/ | c449b93629a5 | openssl | 3.5.7-1~deb13u2 | 1 |
| reportportal/ | b1860ed33071 | openssl | 3.5.8-r0 | 1 |
| reportportal/ | aea8747cb639 | openssl | 3.5.8-r0 | 1 |
| resouer/ | e2f198b49ba7 | openssl | 1.0.1f-1ubuntu2.27+esm16 | 1 |
| restic/ | 136600b6ff68 | openssl | 3.5.8-r0 | 1 |
| restic/ | d2aff06f47eb | openssl | 3.5.8-r0 | 1 |
| resurfaceio/ | d5cda2f64109 | openssl | 3.0.2-0ubuntu1.29 | 1 |
| rezachalak/ | 34f694325191 | openssl | 1.1.1f-1ubuntu2.24+esm5 | 1 |
| rhasspy/ | 69b7f797ae3a | openssl | no fix listed | 1 |
| rhasspy/ | e532f0dbc6b2 | openssl | no fix listed | 1 |
| rhasspy/ | 308b7959a925 | openssl | no fix listed | 1 |
| rm3l/ | 62d1cc4223e5 | openssl | 1.1.1f-1ubuntu2.24+esm5 | 1 |
| rnwood/ | 912304153668 | openssl | no fix listed | 1 |
| robiningelbrecht/ | 40842cdfd616 | openssl | 3.5.8-r0 | 1 |
| robotshop/ | 119b545823cd | openssl | 1.1.1f-1ubuntu2.24+esm5 | 1 |
| robustadev/ | b8d782e568c7 | openssl | 3.5.7-1~deb13u2 | 1 |
| rocketadmin/ | 10955ef540b9 | openssl | no fix listed | 1 |
| rocketchat/ | 44af8ac4e711 | openssl | 3.5.8-r0 | 1 |
| rocketchat/ | 6bc18fb5d0e5 | openssl | 3.5.8-r0 | 1 |
| rocketchat/ | 819771c4abe4 | openssl | 3.5.8-r0 | 1 |
| rocketchat/ | cfba5c20a5cc | openssl | no fix listed | 1 |
| rocketchat/ | c1170bdfe797 | openssl | 3.5.8-r0 | 1 |
| rocm/ | 26212c665aab | openssl | 3.3.7-r1 | 1 |
| rommapp/ | 3512f2ca4557 | openssl | 3.5.8-r0 | 1 |
| rommapp/ | b909e95d1aab | openssl | 3.5.8-r0 | 1 |