StackRadar

CVE-2026-63072

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,366
of 17,828 indexed, latest versions
Container images
3,757
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,366 of 17,828 indexed charts deploy, on 3,757 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+113 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,341
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,403
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm620
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-613
OSV records
ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,366 by stars
ChartLatestAffected imagesRadar Score
speedtestlbenicio-communityVerified publisher0.1.01 of 1See more

speedtest lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/d0ugal/internet-perf-exporter:v0.2.91f5c9a96fe52a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

307
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
lbenicio/stremio-web:latest732f9003de33
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,602
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

33,939
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,493
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

4,316
mosquittoleprechaun-charts0.1.41 of 1See more

mosquitto leprechaun-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
owntracks-exporterleprechaun-charts0.1.111 of 1See more

owntracks-exporter leprechaun-charts 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/owntracks-exporter:0.1.11-de545066099e1abd6d08
openssl@3.0.9-1
no fix listed

Open the chart page →

4,104
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,081
adguard-homelib42Verified publisher2.0.01 of 1See more

adguard-home lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.65d765078d2140
openssl@3.3.4-r0
3.3.7-r1

Open the chart page →

1,206
jackettlib42Verified publisher1.1.01 of 1See more

jackett lib42 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
lib42/jackett:latesta55596cda383
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

4,678
lightlyticslightlytics0.1.212 of 2See more

lightlytics lightlytics 0.1.21

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
openssl@3.0.15-1~deb12u1
no fix listed
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

5,453
amplinguamatics0.12.01 of 4See more

amp linguamatics 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,111
data-factorylinguamatics1.0.11 of 4See more

data-factory linguamatics 1.0.1

1 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,111
delugelinkding0.2.31 of 1See more

deluge linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,582
excalidrawlinkding0.2.31 of 1See more

excalidraw linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
excalidraw/excalidraw:latestf7ee194addd6
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

990
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

38,690
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.41 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

1 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,999
listmonklistmonk-chartVerified publisher2.0.11 of 2See more

listmonk listmonk-chart 2.0.1

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
listmonk/listmonk:v6.0.0bf3903d54a46
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,712
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,168
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,560
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,006
liturgical-appliturgical0.9.01 of 1See more

liturgical-app liturgical 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

955
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29

Open the chart page →

10,874
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,562
pagesliviu884422-pages1.0.02 of 3See more

pages liviu884422-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

20,350
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

13,114
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,486
homerlmatfyVerified publisher0.1.11 of 1See more

homer lmatfy 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
b4bz/homer:v25.02.2c367265313f9
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

491
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,681
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,395
mt-mcp-grafanaloafoe0.10.01 of 2See more

mt-mcp-grafana loafoe 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
grafana/mcp-grafana:0.14.042f541f22063
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

1,986
mt-mcp-proxyloafoe0.3.01 of 2See more

mt-mcp-proxy loafoe 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/github/github-mcp-server:latest508a0857ec76
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

502
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

949
locust-pluginslocust-pluginsVerified publisher0.0.41 of 3See more

locust-plugins locust-plugins 0.0.4

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
locustio/locust:2.24.151d866285170
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

7,583
sonarrloeken-at-homeVerified publisher4.0.181 of 1See more

sonarr loeken-at-home 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
loeken/sonarr:4.0.18ad0528ab7ba0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

859
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

33,939
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

804
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

2,568
elasticvuelogic3579Verified publisher1.15.01 of 1See more

elasticvue logic3579 1.15.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
cars10/elasticvue:1.15.0efddf4fa0fd8
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,083
nightingalelogic3579Verified publisher0.3.13 of 6See more

nightingale logic3579 0.3.1

3 of the 6 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
flashcatcloud/categraf:latest42e6ab16472e
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
library/redis:6.2e7b96daa9a18
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

9,147
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,511
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29

Open the chart page →

6,727
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

6,619
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

23,820
logtidelogtideVerified publisher2.1.143 of 4See more

logtide logtide 2.1.14

3 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,823
clickhouselohmag0.2.01 of 1See more

clickhouse lohmag 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.17ab1738a64b70
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

5,953
allure_docker_servicelovemew67Verified publisher0.0.11 of 1See more

allure_docker_service lovemew67 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.27.00815040339a9
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

62,599
oncall-hobbylovemew67Verified publisher0.0.51 of 2See more

oncall-hobby lovemew67 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/redis:7.0.15352c1fdadc91
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

5,908
vulnerability-scaninglovemew67Verified publisher0.0.31 of 2See more

vulnerability-scaning lovemew67 0.0.3

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.35.14154286c0209
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15

Open the chart page →

5,280

Container images carrying it

3,757 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.8-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.8-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r1
1
registry.k8s.io/kwok/kwok:v0.8.06d25aa8fbdfe
openssl@3.5.7-r0
3.5.8-r0
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.8-r0
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.