StackRadar

CVE-2026-63072

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,442
of 17,813 indexed, latest versions
Container images
3,742
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,442 of 17,813 indexed charts deploy, on 3,742 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,299
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,424
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm620
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-619
OSV records
ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,442 by stars
ChartLatestAffected imagesRadar Score
arlas-uisarlas-stackVerified publisher28.9.03 of 4See more

arlas-uis arlas-stack 28.9.0

3 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
gisaia/arlas-wui:28.0.3b83b3e067173
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
openssl@3.5.7-r0
3.5.8-r0
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,453
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

23,475
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

3,745
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

22,799
assemblylineassemblylineVerified publisher7.4.206 of 12See more

assemblyline assemblyline 7.4.20

6 of the 12 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
cccs/assemblyline-core:4.7.4.stable20098127270065
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-rust:4.7.4.stable202be5e6a57427
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-socketio:4.7.4.stable202b88493b62f7
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui:4.7.4.stable20efa75509b854
openssl@3.0.20-1~deb12u2
no fix listed
cccs/assemblyline-ui-frontend:4.7.4.stable208f3de0b45727
openssl@3.5.7-r0
3.5.8-r0
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

12,874
dltkvassist-iot-data-integrity-verification0.2.03 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

194,425
dltflassist-iot-dlt-based-fl0.2.03 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
openssl@1.0.2g-1ubuntu4.13
1.0.2g-1ubuntu4.20+esm18
hyperledger/fabric-couchdb:0.4.15f6c724592abf
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm18

Open the chart page →

194,425
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

9,446
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

13,419
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

10,189
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

88,229
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

8,074
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

7,994
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

5,390
smartorchestratorassist-iot-smart-orchestrator4.0.06 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

6 of the 14 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
openssl@3.0.11-1~deb12u2
no fix listed
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssl@3.0.9-1
no fix listed
devopsfaith/krakend:latestf8bdaa8a1a43
openssl@3.3.3-r0
3.3.7-r1
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mongo:4.4.66efa05203990
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

46,026
videoaugmentationassist-iot-video-augmentation0.1.02 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm5
bluenviron/mediamtx:latest-ffmpeg9d148b5f2990
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

77,375
account-monitorastria0.0.11 of 1See more

account-monitor astria 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,982
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
openssl@3.0.2-0ubuntu1.8
3.0.2-0ubuntu1.29
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

32,762
auctioneerastria0.0.21 of 1See more

auctioneer astria 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,231
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v6.1.0-rc0a604aefa3fae
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

3,312
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,207
evm-rollupastria4.1.02 of 2See more

evm-rollup astria 4.1.0

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.8-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

4,044
evm-stackastria5.0.32 of 2See more

evm-stack astria 5.0.3

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
openssl@3.5.0-r0
3.5.8-r0
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

4,044
flame-rollupastria0.1.32 of 2See more

flame-rollup astria 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
openssl@3.0.15-1~deb12u1
no fix listed
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

3,887
graph-nodeastria0.2.22 of 3See more

graph-node astria 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
graphprotocol/graph-node:latestb0436347fb24
openssl@3.0.20-1~deb12u2
no fix listed
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,629
hermesastria0.7.11 of 1See more

hermes astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15

Open the chart page →

2,020
hyperlane-agentsastria0.1.41 of 2See more

hyperlane-agents astria 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

2,561
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
openssl@3.3.2-r4
3.3.7-r1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

6,511
sequencer-relayerastria2.0.01 of 1See more

sequencer-relayer astria 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

1,982
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

9,473
attestkeepattestkeepVerified publisher1.1.12 of 2See more

attestkeep attestkeep 1.1.1

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/postgres:16.15-alpinecf78e76683b9
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/attestkeep/attestkeep-k8s:1.1.110ce4cac41c4
openssl@3.3.7-r0
3.3.7-r1

Open the chart page →

860
auth0-operatorauth0-operator1.4.121 of 1See more

auth0-operator auth0-operator 1.4.12

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/alethic/auth0-operator-image:1.4.122468990a8521
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

760
autopushautopushVerified publisher0.0.492 of 4See more

autopush autopush 0.0.49

2 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

3,079
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29

Open the chart page →

6,980
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

6,302
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
wettyoss/wetty:latest7423b3d40ba2
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,216
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,947
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
openssl@3.0.15-1~deb12u1
no fix listed
kuzwolka/aws9:news3e8880fbbb96
openssl@3.0.15-1~deb12u1
no fix listed
kuzwolka/aws9:blog4a7707410bf1
openssl@3.0.15-1~deb12u1
no fix listed
kuzwolka/aws9:shop84a9d9766345
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

18,364
aws-web-service-proxifiedaws-web-service-proxified1.8.01 of 2See more

aws-web-service-proxified aws-web-service-proxified 1.8.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/httpd:latest979c38c2228d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,065
azp-agentazp-agent1.2.01 of 1See more

azp-agent azp-agent 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
cheveo/azp-agent:1.0.282240f890884
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29

Open the chart page →

3,333
kubernetes-providerazureappconfiguration-kubernetesprovider2.6.71 of 1See more

kubernetes-provider azureappconfiguration-kubernetesprovider 2.6.7

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-app-configuration/kubernetes-provider:2.6.7da4db80de17e
openssl@3.3.7-4.azl3
3.3.7-6

Open the chart page →

159
azurefile-csi-driverazurefile-csi-driverVerified publisher1.35.76 of 7See more

azurefile-csi-driver azurefile-csi-driver 1.35.7

6 of the 7 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.35.76e43ba0bd009
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.17.0b767078c36e0
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-provisioner:v6.3.09915a2058ad6
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-resizer:v2.2.04bfe19fe8919
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-snapshotter:v8.5.08b3ce8339944
openssl@3.3.7-4.azl3
3.3.7-6
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.19.0bd19535678a8
openssl@3.3.7-4.azl3
3.3.7-6

Open the chart page →

1,285
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,276
ragflowbaboulinet0.1.11 of 5See more

ragflow baboulinet 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
infiniflow/infinity:v0.7.0992c87a68612
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.29

Open the chart page →

6,083
backstage-pyactionsbackstage-pyactionsVerified publisher0.1.01 of 1See more

backstage-pyactions backstage-pyactions 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
mawad98/backstage-pyactions:demo99422c56a274
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,800
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

6,302
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

20,881
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,737
mealiebdclark-helm-chartsVerified publisher0.1.151 of 1See more

mealie bdclark-helm-charts 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,094
mosquittobdclark-helm-chartsVerified publisher0.6.11 of 1See more

mosquitto bdclark-helm-charts 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.22212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149

Container images carrying it

3,742 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/mollyim/mollysocket:1.7.1c675622546a4
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/mondu-ai/gar-credential-provider:latest25090d37afa9
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
openssl@3.5.1-1
3.5.7-1~deb13u2
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
ghcr.io/mt190502/docker-anki-sync-server:25.09.2824245fd5a57
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
openssl@3.0.18-1~deb12u2
no fix listed
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0dcb8c731bb1b
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.15
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
openssl@3.0.13-1~deb12u1
no fix listed
1
ghcr.io/nicholaswilde/writefreely:version-0.13.1c3c8481b7e56
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm10
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/niklas-letz/cert-manager-webhook-solidserver:1.0.2f19a306ce759
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/nimbolus/terraform-backend:0.2.2bf876252fbe1
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/nmshd/backbone-admin-cli:7.2.1f7d095c04a75
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
ghcr.io/nmshd/backbone-admin-ui:7.2.169c9f075d2d9
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nmshd/backbone-consumer-api:7.2.1b8f0ce01d057
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nmshd/backbone-database-migrator:7.2.12c0c5e022714
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nmshd/backbone-event-handler:7.2.1f4d6a2006530
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nmshd/backbone-housekeeper:7.2.11c1dfe35447f
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nmshd/backbone-identity-deletion-jobs:7.2.1da69941fa6b8
openssl@3.5.6-1~deb13u2+dhi1
3.5.7-1~deb13u2
1
ghcr.io/nnstd/glauth:2.52e6e09fa77dd
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/nowakeai/kube-insight:v0.1.475849fe6548a
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/obeone/ollama-exporter:latestf43af285c6e0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/obolnetwork/remote-signer:v0.4.0534baa453d3d
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/observal/observal-api:1.13.1153b8b893232
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/observal/observal-web:1.13.1738acf65cba7
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/okteto/buildkit:0.0.0-2026-08-03:0.0.0-2026-08-1714527ca5d2a9
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/frontend:0.0.0-2026-08-17c18f4a1bc90a
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/ingress-nginx-chroot:0.0.0-2026-08-17265eedb3954b
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/okteto/redis:0.0.0-2026-08-03:0.0.0-2026-08-1761a0169cf291
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/okteto/registry:0.0.0-2026-08-1769131511501f
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
openssl@3.0.14-1~deb12u2
no fix listed
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
openssl@3.0.20-1~deb12u1
no fix listed
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.