StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,842
of 17,797 indexed, latest versions
Container images
3,070
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 2,842 of 17,797 indexed charts deploy, on 3,070 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+60 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,863
opensslapk3.5.0-r0, 3.5.1-r0, 3.5.2-r0, 3.5.4-r0+4 more3.5.8-r01,173
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-623
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

2,842 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,070 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/kube-state-metrics:204a3044b384b
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:latestbbd4e17f1ef8
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r56dabb4a2088c
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/minio:2025.7.23-debian-12-r08935e75fa5d1
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/mongodb:latestb0652af9c8d0
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/mysql:8.4.5-debian-12-r07089d796fc9b
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/nginx:1.27.1934d1acd5ca8
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
openssl@3.0.17-1~deb12u1
no fix listed
1
bitnamilegacy/pgbouncer:1.23.192356da09704
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.