StackRadar

CVE-2026-63072

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,320
of 17,832 indexed, latest versions
Container images
3,734
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-63072 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,320 of 17,832 indexed charts deploy, on 3,734 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+114 more1.0.1f-1ubuntu2.27+esm16, 1.0.2g-1ubuntu4.20+esm18, 1.1.1-1ubuntu2.1~18.04.23+esm10, 1.1.1f-1ubuntu2.24+esm5+4 more2,331
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,390
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 more1.0.2n-1ubuntu5.13+esm620
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-613
OSV records
ALPINE-CVE-2026-63072DEBIAN-CVE-2026-63072UBUNTU-CVE-2026-63072AZL-97947ECHO-aa38-89d5-f024
Also known as
USN-8678-1, USN-8678-2

Charts affected

3,320 by stars
ChartLatestAffected imagesRadar Score
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
openssl@1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.24+esm5
flyway/flyway:6.4.422d97ceb0c47
openssl@1.1.1-1ubuntu2.1~18.04.5
1.1.1-1ubuntu2.1~18.04.23+esm10

Open the chart page →

20,372
tiktikVerified publisher2026.8.262043231 of 1See more

tik tik 2026.8.26204323

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/metio/tik:2026.8.2618070677f9ee7821d7
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

362
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,824
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

5,728
todoapitodoapi-appVerified publisher0.1.01 of 2See more

todoapi todoapi-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
openssl@1.1.1-1ubuntu2.1~18.04.23
openssl1.0@1.0.2n-1ubuntu5.13
1.1.1-1ubuntu2.1~18.04.23+esm10
1.0.2n-1ubuntu5.13+esm6

Open the chart page →

6,923
todolist-charttodolist-chart0.1.74 of 10See more

todolist-chart todolist-chart 0.1.7

4 of the 10 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
openssl@3.5.1-1
3.5.7-1~deb13u2
erenozcan17/go_backend:v4.250b4f23422b6
openssl@3.5.1-r0
3.5.8-r0
erenozcan17/react_frontend:v4.56e1b14973f9b
openssl@3.5.1-r0
3.5.8-r0
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,110
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,219
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,116
token-servertoken-server1.0.91 of 1See more

token-server token-server 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
udhos/token-server:1.0.9728013f2fac1
openssl@3.5.2-r0
3.5.8-r0

Open the chart page →

1,249
netbirdtotmicro1.8.23 of 4See more

netbird totmicro 1.8.2

3 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
netbirdio/management:0.60.252682e5f48f9
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
netbirdio/relay:0.60.2a10762533793
openssl@3.0.17-1~deb12u3
no fix listed
netbirdio/signal:0.60.267176bcbf6ab
openssl@3.0.17-1~deb12u3
no fix listed

Open the chart page →

6,131
hub-managertraefikVerified publisher1.0.01 of 1See more

hub-manager traefik 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

649
traefik-external-dns-operatortraefik-external-dns-operator1.0.11 of 1See more

traefik-external-dns-operator traefik-external-dns-operator 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ybucci/traefik-external-dns-operator:1.0.0f1fcc7c8d9fd
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,229
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,672
orchestratremolo3.1.561 of 5See more

orchestra tremolo 3.1.56

1 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,137
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29

Open the chart page →

3,116
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,380
trident-protect-bxp-previewtrident-protect100.2511.0-bxp-preview1 of 3See more

trident-protect-bxp-preview trident-protect 100.2511.0-bxp-preview

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v1.0.058b9fac358bd
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

2,202
trident-protect-consoletrident-protect100.2609.0-console1 of 3See more

trident-protect-console trident-protect 100.2609.0-console

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v3.0.0cad26cd945d1
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,964
gtm-server-container-clustertrieb-work0.1.81 of 1See more

gtm-server-container-cluster trieb-work 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

513
saleor-appstrieb-work0.6.04 of 5See more

saleor-apps trieb-work 0.6.0

4 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
openssl@3.0.17-1~deb12u3
no fix listed
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
openssl@3.3.3-r0
3.3.7-r1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
openssl@3.3.3-r0
3.3.7-r1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

7,525
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
openssl@3.3.5-r0
3.3.7-r1

Open the chart page →

1,230
trivy-webhook-aws-security-hubtrivy-webhook-aws-security-hubVerified publisher0.1.201 of 1See more

trivy-webhook-aws-security-hub trivy-webhook-aws-security-hub 0.1.20

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

618
trowtrow0.13.01 of 1See more

trow trow 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,345
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

17,592
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,082
tfy-logstruefoundryVerified publisher0.1.212 of 3See more

tfy-logs truefoundry 0.1.21

2 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/timberio/vector:v0.50.05833723de9e4
openssl@3.5.4-r0
3.5.8-r0
public.ecr.aws/truefoundrycloud/timberio/vector:v0.52.088b8dc80ae74
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,036
truefoundry-monitoringtruefoundryVerified publisher0.1.63 of 8See more

truefoundry-monitoring truefoundry 0.1.6

3 of the 8 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
openssl@3.5.4-r0
3.5.8-r0
public.ecr.aws/truefoundrycloud/timberio/vector:v0.52.088b8dc80ae74
openssl@3.5.6-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

4,601
bobby-apitumogroup1.0.11 of 1See more

bobby-api tumogroup 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
sondresjo/bobby-api:latestfe534731909a
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

2,371
admin-dashboardtwenty20-helm-chartsVerified publisher1.1.01 of 1See more

admin-dashboard twenty20-helm-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29.5-alpine-slim08c2bc93448b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

388
twentytwenty-crm0.1.113 of 4See more

twenty twenty-crm 0.1.11

3 of the 4 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
openssl@3.5.7-r0
3.5.8-r0
redis/redis-stack-server:7.2.0-v10e44b2b49d059
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
twentycrm/twenty:v2.22.0e7d9948bf284
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,689
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,558
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,721
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm5

Open the chart page →

4,178
tyk-control-planetyk-helm5.3.02 of 7See more

tyk-control-plane tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
tykio/tyk-dashboard:v5.13.10e03b94c153d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
openssl@3.5.6-1~deb13u2+fips+dhi1
3.5.7-1~deb13u2

Open the chart page →

3,285
tyk-dashboardtyk-helm5.3.01 of 1See more

tyk-dashboard tyk-helm 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
tykio/tyk-dashboard:v5.13.10e03b94c153d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

825
tyk-data-planetyk-helm5.3.01 of 3See more

tyk-data-plane tyk-helm 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
openssl@3.5.6-1~deb13u2+fips+dhi1
3.5.7-1~deb13u2

Open the chart page →

1,020
tyk-dev-portaltyk-helm5.3.01 of 2See more

tyk-dev-portal tyk-helm 5.3.0

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
tykio/portal:v1.18.092509e00e618
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

926
tyk-stacktyk-helm5.3.02 of 7See more

tyk-stack tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
tykio/tyk-dashboard:v5.13.10e03b94c153d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
openssl@3.5.6-1~deb13u2+fips+dhi1
3.5.7-1~deb13u2

Open the chart page →

3,219
umbrella-chartumbrella-chartVerified publisher0.1.13 of 5See more

umbrella-chart umbrella-chart 0.1.1

3 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
hassroutyyoussef/accountservice:latest1f01edf1ee0c
openssl@3.0.15-1~deb12u1
no fix listed
hassroutyyoussef/orderservice:latest2fc3d1617928
openssl@3.0.15-1~deb12u1
no fix listed
hassroutyyoussef/userservice:lateste0392e2b4a90
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

7,674
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

850
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,574
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

8,743
rstudiouninettsigma21.3.61 of 3See more

rstudio uninettsigma2 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
sigma2as/rstudio-proxy:20260818-1df6a44d899e81ee3eb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

847
sparkuninettsigma21.1.41 of 3See more

spark uninettsigma2 1.1.4

1 of the 3 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
library/nginx:1.31.3-alpine4a73073bd557
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

847
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

355
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,065
excalidashunxwaresVerified publisher2026.2.52 of 2See more

excalidash unxwares 2026.2.5

2 of the 2 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
openssl@3.5.5-r0
3.5.8-r0
zimengxiong/excalidash-frontend:0.4.27242629350b06
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,625
fossflowunxwaresVerified publisher2026.2.11 of 1See more

fossflow unxwares 2026.2.1

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
stnsmith/fossflow:lateste448ab346cb3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

162
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
openssl@3.0.17-1~deb12u1
no fix listed

Open the chart page →

5,314
opencloudunxwaresVerified publisher0.2.37 of 13See more

opencloud unxwares 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-63072.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.15
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
openssl@3.0.15-1~deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

44,878

Container images carrying it

3,734 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

No deployed image carries CVE-2026-63072.

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.