StackRadar

CVE-2026-63072

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,414
of 17,821 indexed, latest versions
Container images
3,782
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,414 of 17,821 indexed charts deploy, on 3,782 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+113 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,343
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,425
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm621
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-614
OSV records
ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,414 by stars
ChartLatestAffected imagesRadar Score
kminionxxl-job-adminVerified publisher0.13.01 of 1See more

kminion xxl-job-admin 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
redpandadata/kminion:v2.3.256da99e8d0d3
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

668
nightingalexxl-job-adminVerified publisher0.2.113 of 6See more

nightingale xxl-job-admin 0.2.11

3 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
no fix listed
library/redis:6.2d2ad7b21cafa
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,743
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

3,197
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

1,257
prometheus-monitoring-stackyotron-helm-charts1.2.01 of 3See more

prometheus-monitoring-stack yotron-helm-charts 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

936
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

2,638
zahori-schedulerzahoriVerified publisher1.0.11 of 1See more

zahori-scheduler zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
zahoriaut/zahori-scheduler:1.0.047d0979b1184
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

2,485
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,710
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

411
homerzekker6Verified publisher8.35.01 of 1See more

homer zekker6 8.35.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
b4bz/homer:v26.08.3febc8967c9f7
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,424
zipkinzipkinVerified publisher0.5.01 of 1See more

zipkin zipkin 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
openzipkin/zipkin-slim:3.6.0a69e1057df36
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,191
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm10
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

9,297
zoo-project-druzoo-projectOfficialVerified publisher0.10.44 of 6See more

zoo-project-dru zoo-project 0.10.4

4 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
curlimages/curl:8.21.07c12af72ceb3
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.4-alpine3.249a8afca54e78
openssl@3.5.7-r0
3.5.8-r0
library/rabbitmq:4.3.2-alpine835cbc6fabce
openssl@3.5.7-r0
3.5.8-r0
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

7,966

Container images carrying it

3,782 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/wez/govee2mqtt:2026.03.25-ab9deb66a9d9fe330574
openssl@3.0.18-1~deb12u2
no fix listed
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
openssl@3.5.0-r0
3.5.8-r0
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/wiremind/ovh-exporter:v2.3.1609f955bd977
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm10
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
openssl@3.0.17-1~deb12u2
no fix listed
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
openssl@3.0.19-1~deb12u2
no fix listed
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/zalando/postgres-operator:v2.0.275f69eac43ac
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/zalando/skipper:v0.27.883a357a2a4bef
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/zapier/kubechecks:latest60cea46ce830
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/zazuko/fuseki-geosparql:v5.2.06fbd8983f750
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.2ae9ae0925ff8
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.29
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.29a32b89c0c19
openssl@3.5.0-r0
3.5.8-r0
1
mcr.microsoft.com/acstor/local-csi-driver:v0.3.0f9af53a79fd1
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/acstor/local-csi-manager:v0.3.04f464b52ba85
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/application-lb/images/alb-controller-crds:1.12.14dcf198fcb7c
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/azure-app-configuration/kubernetes-provider:2.6.7da4db80de17e
openssl@3.3.7-4.azl3
3.3.7-6
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm5
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
openssl@3.5.7-r0
3.5.8-r0
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
1.1.1-1ubuntu2.1~18.04.23+esm10
1.0.2n-1ubuntu5.13+esm6
1
mcr.microsoft.com/mssql/server:2022-latest4402d880dd4c
openssl@3.0.2-0ubuntu1.29
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.