CVE-2026-63074
MediumAdvisory
Published 25 Aug 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.9
- base score, highest
- EPSS
- 0.005
- 41st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,855
- of 17,790 indexed, latest versions
- Container images
- 3,100
- deployed by those charts
- Fix available
- 3 of 4
- affected packages
CVE-2026-63074 affecting package openssl for versions less than 3.3.7-6
Carried by container images the latest versions of 2,855 of 17,790 indexed charts deploy, on 3,100 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| openssldeb | 3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+60 more | 3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2 | 1,876 |
| opensslapk | 3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more | 3.5.8-r0 | 1,190 |
| nodejsdeb | 4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 more | no fix listed | 11 |
| opensslrpm | 3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl3 | 3.3.7-6 | 23 |
- OSV records
- ALPINE-CVE-2026-63074DEBIAN-CVE-2026-63074UBUNTU-CVE-2026-63074AZL-97944ECHO-8298-2fc4-74d4
- Also known as
- USN-8678-1
Charts affected
2,855 by stars
Container images carrying it
3,100 by charts deploying them
A fixed version is listed for 3 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 60566529446a | openssl | 3.0.13-0ubuntu3.15 | 3 |
| quay.io/ | 721b5c9634d4 | openssl | 3.0.13-0ubuntu3.15 | 3 |
| quay.io/ | aa61fffb8ae8 | openssl | 3.5.8-r0 | 3 |
| quay.io/ | c63823af3835 | openssl | 3.5.8-r0 | 3 |
| quay.io/ | 9795f3f9f031 | openssl | 3.0.13-0ubuntu3.15 | 3 |
| quay.io/ | 01d5d8c4cecb | openssl | 3.0.13-0ubuntu3.15 | 3 |
| quay.io/ | f296c2ec5db7 | openssl | 3.0.2-0ubuntu1.29 | 3 |
| quay.io/ | 9d25865295af | openssl | 3.0.13-0ubuntu3.15 | 3 |
| quay.io/ | ea6dd1e4ce71 | openssl | 3.0.13-0ubuntu3.15 | 3 |
| quay.io/ | 709c7da19c5a | openssl | no fix listed | 3 |
| quay.io/ | 522738d5285e | openssl | 3.5.8-r0 | 3 |
| alazidis/ | 0e8c84152201 | openssl | 3.0.13-0ubuntu3.15 | 2 |
| alpine/ | 4f9488b7295b | openssl | 3.5.8-r0 | 2 |
| alpine/ | 048f8d9c8cc7 | openssl | 3.5.8-r0 | 2 |
| alpine/ | 9ccd82364762 | openssl | 3.5.8-r0 | 2 |
| alpine/ | ec8f734b0a10 | openssl | 3.5.8-r0 | 2 |
| apache/ | 9ee5df1611f9 | openssl | 3.0.13-0ubuntu3.15 | 2 |
| apache/ | 5c5efa4c7f2a | openssl | no fix listed | 2 |
| apache/ | 77e3df905404 | openssl | 3.5.8-r0 | 2 |
| apache/ | 7cdfd8deec92 | openssl | 3.0.2-0ubuntu1.29 | 2 |
| apache/ | 319cd8a81ed1 | openssl | 3.0.13-0ubuntu3.15 | 2 |
| apache/ | ae0b86d3c4d0 | openssl | 3.0.13-0ubuntu3.15 | 2 |
| apecloud/ | 94041b080510 | openssl | 3.5.8-r0 | 2 |
| aquasec/ | 62b1e65e8869 | openssl | 3.5.8-r0 | 2 |
| axllent/ | c96991d9bef7 | openssl | 3.5.8-r0 | 2 |
| bitnamilegacy/ | 00176a47afa0 | openssl | no fix listed | 2 |
| bitnamilegacy/ | 33ce23601fc9 | openssl | no fix listed | 2 |
| bitnamilegacy/ | d3bf3910f148 | openssl | no fix listed | 2 |
| bitnamilegacy/ | 94bc968141e7 | openssl | no fix listed | 2 |
| bitnamilegacy/ | f12387ec882b | openssl | no fix listed | 2 |
| bitnamilegacy/ | 5927ff3702df | openssl | no fix listed | 2 |
| bitnamilegacy/ | 32869e769b7e | openssl | no fix listed | 2 |
| cfssl/ | c9018c2ddf0b | openssl | no fix listed | 2 |
| chromedp/ | 313ed7255ae1 | openssl | 3.5.7-1~deb13u2 | 2 |
| clamav/ | 629a3050df6a | openssl | 3.5.8-r0 | 2 |
| clickhouse/ | 258d43821508 | openssl | 3.5.8-r0 | 2 |
| cloudflare/ | 6d91c121b803 | openssl | 3.5.7-1~deb13u2 | 2 |
| cribl/ | 044f9a5fac9a | openssl | 3.0.13-0ubuntu3.15 | 2 |
| curlimages/ | 4026b29997dc | openssl | 3.5.8-r0 | 2 |
| curlimages/ | b3f1fb2a51d9 | openssl | 3.5.8-r0 | 2 |
| datagrok/ | f5876d3aebb8 | openssl | 3.0.2-0ubuntu1.29 | 2 |
| dunglas/ | 916834e49961 | openssl | 3.5.8-r0 | 2 |
| emberstack/ | 51dbd5880929 | openssl | 3.0.13-0ubuntu3.15 | 2 |
| fireflyiii/ | fe4ecec4c2ba | openssl | 3.5.7-1~deb13u2 | 2 |
| fireflyiii/ | ab52bf932546 | openssl | 3.5.7-1~deb13u2 | 2 |
| gisaia/ | b83b3e067173 | openssl | 3.5.8-r0 | 2 |
| gisaia/ | a35977a5bb7d | openssl | 3.5.8-r0 | 2 |
| gisaia/ | 1a3cc43d822f | openssl | 3.5.8-r0 | 2 |
| gjeanmart/ | 926264c8f2d1 | openssl | no fix listed | 2 |
| gotenberg/ | 87c16b9f3642 | openssl | 3.5.7-1~deb13u2 | 2 |