StackRadar

CVE-2026-63073

Critical

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,759
of 17,792 indexed, latest versions
Container images
1,642
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63073 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 1,759 of 17,792 indexed charts deploy, on 1,642 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,171
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2437
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-63073DEBIAN-CVE-2026-63073UBUNTU-CVE-2026-63073AZL-97950
Also known as
USN-8678-1

Charts affected

1,759 by stars
ChartLatestAffected imagesRadar Score
opencvecfi20170.1.22 of 7See more

opencve cfi2017 0.1.2

2 of the 7 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/postgres:18.06f3e42ad37de
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2
ghcr.io/cfi2017/opencve-web:3.0.06961eab190a2
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

15,490
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,339
charon-relaycharonOfficialVerified publisher0.8.02 of 2See more

charon-relay charon 0.8.0

2 of the 2 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
alpine/kubectl:1.35.2ec8f734b0a10
openssl@3.5.5-r0
3.5.8-r0
obolnetwork/charon:v1.10.0278c7e2897b6
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,440
dv-podcharonOfficialVerified publisher0.19.12 of 5See more

dv-pod charon 0.19.1

2 of the 5 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
obolnetwork/charon:v1.10.0278c7e2897b6
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
obolnetwork/charon-dkg-sidecar:maine263be0a7440
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

7,501
ghostchart-ghost0.1.52 of 2See more

ghost chart-ghost 0.1.5

2 of the 2 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
openssl@3.5.5-r0
3.5.8-r0
registry.gitlab.com/gitlab-ci-utils/curl-jq:latestb564745b6cb0
openssl@3.5.7-r1
3.5.8-r0

Open the chart page →

4,083
kitchenowlchart-kitchenowl0.1.122 of 2See more

kitchenowl chart-kitchenowl 0.1.12

2 of the 2 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
tombursch/kitchenowl-web:v0.7.8517f808eee66
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

4,829
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,722
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed

Open the chart page →

12,816
radicalecharts-derwitt-devVerified publisher0.1.0-1.0.01 of 1See more

radicale charts-derwitt-dev 0.1.0-1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/kozea/radicale:3.7.600a3d8e1f04b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

426
yas3pcharts-derwitt-devVerified publisher0.3.11 of 1See more

yas3p charts-derwitt-dev 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
denniswitt/yas3p:0.2.488a235619af6
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

737
fhir-server-exporterchglVerified publisher1.2.391 of 1See more

fhir-server-exporter chgl 1.2.39

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/chgl/fhir-server-exporter:v3.0.18b7d58a342e94
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

217
kubevirt-managerchristianhuthVerified publisher0.7.01 of 1See more

kubevirt-manager christianhuth 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
kubevirtmanager/kubevirt-manager:1.5.41b98f1b5977a
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,993
netbird-reverse-proxychristianhuthVerified publisher0.1.01 of 1See more

netbird-reverse-proxy christianhuth 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
netbirdio/reverse-proxy:0.72.43104d5ca3a76
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

935
prometheus-pve-exporterchristianhuthVerified publisher2.10.01 of 1See more

prometheus-pve-exporter christianhuth 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:3.10.04867684c0a93
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

349
ethereumchronicleVerified publisher0.3.11 of 1See more

ethereum chronicle 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ethereum/client-go:v1.16.532b878e4144a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,351
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

6,028
tetragoncilium21.7.11 of 3See more

tetragon cilium2 1.7.1

1 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.7.1afc9458ba4bc
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

232
cinnycinnyVerified publisher0.2.241 of 1See more

cinny cinny 0.2.24

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/cinnyapp/cinny:v4.12.6a7805a8a60ff
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

804
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:mainline-alpinee93571f3d083
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

3,470
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,625
cronjobclouddrove1.0.11 of 1See more

cronjob clouddrove 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

738
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

21,034
hcloud-ccm-mgmtcloudhippieVerified publisher1.11.01 of 1See more

hcloud-ccm-mgmt cloudhippie 1.11.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.37.0c139e7220dbc
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

254
hcloud-csi-mgmtcloudhippieVerified publisher2.10.01 of 5See more

hcloud-csi-mgmt cloudhippie 2.10.0

1 of the 5 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

597
hcloud-csi-usercloudhippieVerified publisher1.8.01 of 3See more

hcloud-csi-user cloudhippie 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.23.0024ea4b07161
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

183
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed

Open the chart page →

27,454
lampcloudnativeapp1.1.01 of 3See more

lamp cloudnativeapp 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/httpd:2.4-alpine1b766f17b840
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,764
mercurecloudnativeapp1.0.21 of 1See more

mercure cloudnativeapp 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
dunglas/mercure:v0916834e49961
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,105
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
nodejs@7.10.1-2nodesource1~xenial1
no fix listed

Open the chart page →

77,816
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
openssl@3.5.1-r0
3.5.8-r0
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

18,374
k8s-monitoring-appcloudscriptVerified publisher1.0.01 of 1See more

k8s-monitoring-app cloudscript 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/cloudscript-technology/k8s-monitoring-app:v0.0.25cab66a6b3574
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,294
cloudvaultcloudvaultOfficialVerified publisher1.0.22 of 3See more

cloudvault cloudvault 1.0.2

2 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/postgres:18.3-alpine54451ecb8ab3
openssl@3.5.6-r0
3.5.8-r0
shyamkrishna21/cloudvault:latestaf2785f5bb71
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,185
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,603
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

70,945
argo-cdcluster-deploy0.3.22 of 3See more

argo-cd cluster-deploy 0.3.2

2 of the 3 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4
quay.io/argoprojlabs/argocd-image-updater:v1.2.13c56f354fac5
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,752
authentikcluster-deploy0.2.01 of 1See more

authentik cluster-deploy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.5.6ed120caf710c
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,509
monitoringcluster-deploy0.3.03 of 11See more

monitoring cluster-deploy 0.3.0

3 of the 11 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
grafana/grafana:12.4.1e932bd6ed0e0
openssl@3.5.5-r0
3.5.8-r0
library/memcached:1.6.41-alpine65c80b311a96
openssl@3.5.6-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

8,219
rustfscluster-deploy0.0.61 of 2See more

rustfs cluster-deploy 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
rustfs/rustfs:1.0.0-rc.3800cf3f352a0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

290
stocksalescluster-deploy0.1.31 of 1See more

stocksales cluster-deploy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
foggbh/stocky:latest8b7a2e5ecf4e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

408
traefikcluster-deploy0.3.01 of 1See more

traefik cluster-deploy 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/traefik:v3.7.109c3b91d5fb77
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

346
clusterfactoryclusterfactory0.2.03 of 5See more

clusterfactory clusterfactory 0.2.0

3 of the 5 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
gitea/act_runner:0.3.1c2a169c5e998
openssl@3.5.5-r0
3.5.8-r0
jenkins/jenkins:2.541.3-jdk21c4098086090c
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

7,193
gitea-jenkinsclusterfactory0.1.13 of 5See more

gitea-jenkins clusterfactory 0.1.1

3 of the 5 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
gitea/act_runner:latestb5c35d6bdbb9
openssl@3.5.6-r0
3.5.8-r0
jenkins/jenkins:2.541.3-jdk21c4098086090c
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

6,982
storage-local-pathcnapVerified publisher1.0.11 of 1See more

storage-local-path cnap 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.3534ff0847cc47
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

753
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

19,454
cobbler-webcobbler0.2.11 of 1See more

cobbler-web cobbler 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
ghcr.io/cobbler/cobbler-web:v1.1.0c17978fb13dd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

371
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,292
ms-catalogs-restcodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-catalogs-rest codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
codedesignplus/ms-catalogs-rest:latest03b80bec4458
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

236
ms-emails-workercodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-emails-worker codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
codedesignplus/ms-emails-worker:latest48fe7e6ceaba
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

248
ms-filestorage-restcodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-filestorage-rest codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
codedesignplus/ms-filestorage-rest:latest7666ccfa0d68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

236
ms-licenses-restcodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-licenses-rest codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-63073.

Container imageDigestPackageFixed in
codedesignplus/ms-licenses-rest:latest52963715c729
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

236

Container images carrying it

1,642 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-63073.

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.