StackRadar

CVE-2026-63075

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,771
of 17,805 indexed, latest versions
Container images
1,641
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63075 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 1,771 of 17,805 indexed charts deploy, on 1,641 images.

Affected packageAffected versionsFixed inImages
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,171
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+10 more3.5.5-1ubuntu3.4, 3.5.7-1~deb13u2433
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-620
OSV records
ALPINE-CVE-2026-63075DEBIAN-CVE-2026-63075UBUNTU-CVE-2026-63075AZL-97938
Also known as
USN-8678-1

Charts affected

1,771 by stars
ChartLatestAffected imagesRadar Score
prowlarrsudo-kraken-prowlarrVerified publisher3.2.11 of 1See more

prowlarr sudo-kraken-prowlarr 3.2.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/home-operations/prowlarr:2.3.01a8a4b11972b
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

879
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,132
svc-lb-muxsvc-lb-mux0.1.31 of 1See more

svc-lb-mux svc-lb-mux 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,475
sveltos-dashboardsveltosVerified publisher1.15.11 of 2See more

sveltos-dashboard sveltos 1.15.1

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
projectsveltos/dashboard:v1.15.01380c9314dd4
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

160
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,773
of-dlswuuper-githubVerified publisher0.1.21 of 2See more

of-dl swuuper-github 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/alpine:3.2214358309a308
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

2,416
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
mikefarah/yq:4cfc4eee65859
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

8,311
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,302
minecraftsyntaxerror404Verified publisher1.2.232 of 2See more

minecraft syntaxerror404 1.2.23

2 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
alpine/curl:8.22.0b9c839d47281
openssl@3.5.7-r0
3.5.8-r0
library/eclipse-temurin:25.0.3_9-jre-alpine-3.2328db6fdf60e3
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

461
teamspeaksyntaxerror404Verified publisher1.0.101 of 1See more

teamspeak syntaxerror404 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/teamspeak:3.13.815acbc64c92f
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

450
vaultwardensyself1.0.01 of 1See more

vaultwarden syself 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
vaultwarden/server:latest094b5689ed81
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,788
poscatechnostructuresVerified publisher1.0.01 of 1See more

posca technostructures 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,112
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,040
tekton-ci-environment-injectortekton-ci-environment-injectorVerified publisher0.2.41 of 1See more

tekton-ci-environment-injector tekton-ci-environment-injector 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

513
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

4,230
pingmetektonops0.1.21 of 1See more

pingme tektonops 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
khaliq/pingme:v0.2.749f96888d2ab
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,255
tekton-stash-and-cachetekton-stash-and-cacheVerified publisher0.2.21 of 1See more

tekton-stash-and-cache tekton-stash-and-cache 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

1,151
tensorzerotensorzero2026.6.02 of 2See more

tensorzero tensorzero 2026.6.0

2 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
tensorzero/gateway:2026.6.0c939db4f27e4
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
tensorzero/ui:2026.6.0f2563d54724e
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

4,078
supabaseteochenglim0.1.23 of 13See more

supabase teochenglim 0.1.2

3 of the 13 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0
supabase/realtime:latestd3aa0c86c7b3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
supabase/storage-api:latestf6c42a04163d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

9,887
terminusterminusVerified publisher1.1.01 of 1See more

terminus terminus 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/terminus-io/enforcer:v1.1.0f21b905610d6
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

640
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,884
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/redis:latest298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

20,465
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,411
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

4,677
openmeteo-exporterth-chartsVerified publisher0.1.61 of 1See more

openmeteo-exporter th-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
thelande/openmeteo_exporter:v1.0.77e9072ace15f
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,382
prusa-exporterth-chartsVerified publisher0.3.01 of 1See more

prusa-exporter th-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
pubeldev/prusa_exporter:2.0.01091665a020a
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

909
the0the0Verified publisher0.9.82 of 9See more

the0 the0 0.9.8

2 of the 9 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/nats:2.10-alpineb83efabe3e7d
openssl@3.5.5-r0
3.5.8-r0
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,528
tikatikaVerified publisher0.3.01 of 1See more

tika tika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/kenchrcum/tika:3.3.0-full708446bc6783
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,822
todolist-charttodolist-chart0.1.74 of 10See more

todolist-chart todolist-chart 0.1.7

4 of the 10 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
openssl@3.5.1-1
3.5.7-1~deb13u2
erenozcan17/go_backend:v4.250b4f23422b6
openssl@3.5.1-r0
3.5.8-r0
erenozcan17/react_frontend:v4.56e1b14973f9b
openssl@3.5.1-r0
3.5.8-r0
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,083
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

3,216
togglr-frontendtogglrVerified publisher1.0.01 of 1See more

togglr-frontend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
gdrocha/togglr-frontend:1.0.0ffbc1571c234
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,114
token-servertoken-server1.0.91 of 1See more

token-server token-server 1.0.9

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
udhos/token-server:1.0.9728013f2fac1
openssl@3.5.2-r0
3.5.8-r0

Open the chart page →

1,247
hub-managertraefikVerified publisher1.0.01 of 1See more

hub-manager traefik 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/traefik/hub-manager:v0.45.1d1cff2560c67
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

649
traefik-secrets-exportertraefik-secrets-exporter0.0.21 of 1See more

traefik-secrets-exporter traefik-secrets-exporter 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,671
apptreenityVerified publisher0.1.532 of 2See more

app treenity 0.1.53

2 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,856
treenitytreenityVerified publisher0.1.32 of 4See more

treenity treenity 0.1.3

2 of the 4 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/postgres:14156f0b253fd6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:alpinebecdda6c7f4b
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,405
orchestratremolo3.1.561 of 5See more

orchestra tremolo 3.1.56

1 of the 5 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/headlamp-k8s/headlamp:v0.45.0db3f0e0fc58d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,011
trident-protecttrident-protect100.2606.01 of 2See more

trident-protect trident-protect 100.2606.0

1 of the 2 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,379
trident-protect-bxp-previewtrident-protect100.2511.0-bxp-preview1 of 3See more

trident-protect-bxp-preview trident-protect 100.2511.0-bxp-preview

1 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v1.0.058b9fac358bd
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

2,201
trident-protect-consoletrident-protect100.2608.0-console1 of 3See more

trident-protect-console trident-protect 100.2608.0-console

1 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,370
gtm-server-container-clustertrieb-work0.1.81 of 1See more

gtm-server-container-cluster trieb-work 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

503
trivy-webhook-aws-security-hubtrivy-webhook-aws-security-hubVerified publisher0.1.201 of 1See more

trivy-webhook-aws-security-hub trivy-webhook-aws-security-hub 0.1.20

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/csepulveda/trivy-webhook-aws-security-hub:v0.1.206836b779b060
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

618
trowtrow0.13.01 of 1See more

trow trow 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,321
tfy-grafanatruefoundryVerified publisher0.1.211 of 3See more

tfy-grafana truefoundry 0.1.21

1 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

1,082
tfy-logstruefoundryVerified publisher0.1.212 of 3See more

tfy-logs truefoundry 0.1.21

2 of the 3 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/timberio/vector:v0.50.05833723de9e4
openssl@3.5.4-r0
3.5.8-r0
public.ecr.aws/truefoundrycloud/timberio/vector:v0.52.088b8dc80ae74
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,036
truefoundry-monitoringtruefoundryVerified publisher0.1.63 of 8See more

truefoundry-monitoring truefoundry 0.1.6

3 of the 8 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
openssl@3.5.4-r0
3.5.8-r0
public.ecr.aws/truefoundrycloud/timberio/vector:v0.52.088b8dc80ae74
openssl@3.5.6-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.1.2716b0b33ff2d
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

4,598
admin-dashboardtwenty20-helm-chartsVerified publisher1.1.01 of 1See more

admin-dashboard twenty20-helm-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.29.5-alpine-slim08c2bc93448b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

388
twentytwenty-crm0.1.112 of 4See more

twenty twenty-crm 0.1.11

2 of the 4 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
library/postgres:16-alpinecf78e76683b9
openssl@3.5.7-r0
3.5.8-r0
twentycrm/twenty:v2.22.0e7d9948bf284
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

5,644
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-63075.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
openssl@3.5.1-r0
3.5.8-r0

Open the chart page →

1,558

Container images carrying it

1,641 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-63075.

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.