StackRadar

CVE-2026-63075

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,758
of 17,803 indexed, latest versions
Container images
1,647
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63075 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 1,758 of 17,803 indexed charts deploy, on 1,647 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,176
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2437
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-63075DEBIAN-CVE-2026-63075UBUNTU-CVE-2026-63075AZL-97938
Also known as
USN-8678-1

Charts affected

1,758 by stars
ChartLatestAffected imagesRadar Score
ld-relayld-relay3.11.11 of 1See more

ld-relay ld-relay 3.11.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
launchdarkly/ld-relay:8.21.08fc1437962a9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

209
mosquittoleprechaun-charts0.1.41 of 1See more

mosquitto leprechaun-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
vaultwardenleprechaun-charts0.1.281 of 1See more

vaultwarden leprechaun-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.1ebdfe70701c6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,076
librenmslibrenms10.1.11 of 5See more

librenms librenms 10.1.1

1 of the 5 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,169
amplinguamatics0.12.01 of 4See more

amp linguamatics 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,109
data-factorylinguamatics1.0.11 of 4See more

data-factory linguamatics 1.0.1

1 of the 4 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/rabbitmq:3-management-alpine606d8c0d6b3c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,109
linode-blockstorage-csi-driverlinode-blockstorage-csi-driverOfficialVerified publisher1.1.41 of 5See more

linode-blockstorage-csi-driver linode-blockstorage-csi-driver 1.1.4

1 of the 5 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
linode/linode-blockstorage-csi-driver:v1.1.409f3282bf53d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,998
listmonklistmonk-chartVerified publisher2.0.12 of 2See more

listmonk listmonk-chart 2.0.1

2 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/postgres:159b1d34adbce1
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
listmonk/listmonk:v6.0.0bf3903d54a46
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,128
pocketbase-halitesql0.0.31 of 1See more

pocketbase-ha litesql 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/litesql/pocketbase-ha:latestc5b28608958b
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,164
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,558
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,004
liturgical-appliturgical0.9.01 of 1See more

liturgical-app liturgical 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

953
livekit-serverlivekit-server1.9.01 of 1See more

livekit-server livekit-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
livekit/livekit-server:v1.9.03602a85840d5
openssl@3.5.0-r0
3.5.8-r0

Open the chart page →

1,560
llmarinerllmariner1.53.11 of 21See more

llmariner llmariner 1.53.1

1 of the 21 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

12,177
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,471
jellyfinlmatfyVerified publisher0.1.31 of 1See more

jellyfin lmatfy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,658
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,805
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,393
local-businesslocal-business0.1.01 of 1See more

local-business local-business 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
alakaganaguathoork/local-business:latest7eb27b0f4a5a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

947
sonarrloeken-at-homeVerified publisher4.0.181 of 1See more

sonarr loeken-at-home 4.0.18

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
loeken/sonarr:4.0.18ad0528ab7ba0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

859
license-serverloftVerified publisher0.6.01 of 1See more

license-server loft 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/license-server:0.6.069ce001bb4b0
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

804
elasticvuelogic3579Verified publisher1.15.01 of 1See more

elasticvue logic3579 1.15.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
cars10/elasticvue:1.15.0efddf4fa0fd8
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,081
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

9,147
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,494
logtidelogtideVerified publisher2.1.143 of 4See more

logtide logtide 2.1.14

3 of the 4 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
openssl@3.5.6-r0
3.5.8-r0
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

2,961
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:latest69a7170eeeda
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,857
redislsst-sqre1.2.11 of 1See more

redis lsst-sqre 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,004
ratelimitlumiumcoVerified publisher0.0.41 of 2See more

ratelimit lumiumco 0.0.4

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,163
lynxpromptlynxpromptVerified publisher0.1.22 of 3See more

lynxprompt lynxprompt 0.1.2

2 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
openssl@3.5.6-r0
3.5.8-r0
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,867
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,699
jellyfinm0nsterrr-jellyfinVerified publisher2.3.51 of 1See more

jellyfin m0nsterrr-jellyfin 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,658
kea-exporterm0nsterrr-kea-exporterVerified publisher2.2.11 of 1See more

kea-exporter m0nsterrr-kea-exporter 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,093
qbittorrentm0nsterrr-qbittorrentVerified publisher7.1.21 of 2See more

qbittorrent m0nsterrr-qbittorrent 7.1.2

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.2.34fcf15b7f265
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

764
recyclarrm0nsterrr-recyclarrVerified publisher2.7.21 of 1See more

recyclarr m0nsterrr-recyclarr 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/recyclarr/recyclarr:8.7.26e69e009e1cd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

241
routinatorm0nsterrr-routinatorVerified publisher2.3.11 of 1See more

routinator m0nsterrr-routinator 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
nlnetlabs/routinator:v0.15.2bc57d6e973c3
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

742
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-backend:latest4adf360dbf1e
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

24,748
docker-mailservermailserverVerified publisher0.2.652 of 9See more

docker-mailserver mailserver 0.2.65

2 of the 9 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
jeboehm/mailserver-web:5.0.929da13edf5aa8
openssl@3.5.2-r0
3.5.8-r0
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

11,536
plane-mcp-servermakeplaneVerified publisher1.0.01 of 2See more

plane-mcp-server makeplane 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
makeplane/plane-mcp-server:v0.3.071b7252adef0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,647
novosgamarcusrepo0.1.11 of 2See more

novosga marcusrepo 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
novosga/novosga:latest34b9acbe6e51
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,726
marge-botmarge-bot-helm1.3.51 of 1See more

marge-bot marge-bot-helm 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.16.0b59f01bc0418
openssl@3.5.1-1+deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,619
ejabberdmartialblog0.3.11 of 1See more

ejabberd martialblog 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/processone/ejabberd:latest5aeb0faa39cf
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

386
mayastormayastorVerified publisher2.12.13 of 31See more

mayastor mayastor 2.12.1

3 of the 31 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
openebs/alpine-bash:4.6.0366d6c5f18c3
openssl@3.5.7-r0
3.5.8-r0
openebs/alpine-sh:4.6.0640c187dccda
openssl@3.5.7-r0
3.5.8-r0
openebs/provisioner-localpv:4.6.099f5116f5cb8
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

21,596
mcroutermcrouterVerified publisher0.2.01 of 2See more

mcrouter mcrouter 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/memcached:1.6.4226983a43c918
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,347
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

9,816
mdai-hubmdai-hubVerified publisher0.10.11 of 14See more

mdai-hub mdai-hub 0.10.1

1 of the 14 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,920
dependency-trackmediamarktsaturn1.9.22 of 2See more

dependency-track mediamarktsaturn 1.9.2

2 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.14.21ba4f004e1ec
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
dependencytrack/frontend:4.14.200560b57a6cf
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

3,855
profilarrmedia-servarrVerified publisher2.3.11 of 1See more

profilarr media-servarr 2.3.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/dictionarry-hub/profilarr:2.2.0ddcdd0f34004
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

337
tinymediamanagermedia-servarrVerified publisher1.6.31 of 2See more

tinymediamanager media-servarr 1.6.3

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

8,088
memgraph-mcpmemgraphVerified publisher1.0.01 of 1See more

memgraph-mcp memgraph 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
memgraph/mcp-memgraph:0.1.13ecdf7faea3f7
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,725
merminmerminOfficialVerified publisher0.4.11 of 1See more

mermin mermin 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/elastiflow/mermin:v0.4.1205053c8a3e2
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

636

Container images carrying it

1,647 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-63075.

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.