StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,945
of 17,821 indexed, latest versions
Container images
3,287
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 2,945 of 17,821 indexed charts deploy, on 3,287 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+59 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,849
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,408
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-613
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

2,945 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,287 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
artifacthub/scanner:v1.23.02d8365601f0e
openssl@3.5.7-r0
3.5.8-r0
1
artifacthub/tracker:v1.23.05368d21a6e5c
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssl@3.0.11-1~deb12u2
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
assistiot/identity-manager_db:latest0d3e6d35f168
openssl@3.0.11-1~deb12u2
no fix listed
1
assistiot/location_processing:lateste9bae124095f
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29
1
assistiot/open_api_backend:1.1.230812ba93555
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
openssl@3.0.11-1~deb12u2
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
openssl@3.0.11-1~deb12u2
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssl@3.0.9-1
no fix listed
1
athou/commafeed:6.2.0-postgresql5e388351df1a
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
atlassian/confluence-server:7.10.03b9222ab32ef
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29
1
atlassian/jira-software:8.14.037bc46cbec1a
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
atlassian/jira-software:9.7.264a75aa4ec4e
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
automatischio/automatisch:0.15.03bace7a12d5f
openssl@3.3.3-r0
3.3.7-r1
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
openssl@3.0.13-1~deb12u1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
openssl@3.0.9-1
no fix listed
1
avzini/web-app:latestf40b30210ed0
openssl@3.0.11-1~deb12u2
no fix listed
1
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
openssl@3.5.5-r0
3.5.8-r0
1
axllent/mailpit:v1.31.0c96991d9bef7
openssl@3.5.7-r0
3.5.8-r0
1
b3log/siyuan:v3.8.36ab17ed3ca40
openssl@3.5.7-r0
3.5.8-r0
1
b3log/siyuan:v3.1.2595c0d129bc19
openssl@3.3.3-r0
3.3.7-r1
1
b4bz/homer:v25.02.2c367265313f9
openssl@3.3.3-r0
3.3.7-r1
1
baserow/backend:2.3.37c00549b3a6f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
baserow/backend:1.31.1e0b3c8130b91
openssl@3.0.15-1~deb12u1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
openssl@3.0.15-1~deb12u1
no fix listed
1
baserow/web-frontend:2.3.3566d24c7d9f5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
beanbag/reviewboard:latest6b840f546e1c
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
openssl@3.5.1-1
3.5.7-1~deb13u2
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
openssl@3.0.16-1~deb12u1
no fix listed
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
openssl@3.5.0-r0
3.5.8-r0
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
openssl@3.0.17-1~deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.301249fc292e84
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.3164614ef8290f
openssl@3.0.15-1~deb12u1
no fix listed
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
openssl@3.0.14-1~deb12u2
no fix listed
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
openssl@3.0.11-1~deb12u2
no fix listed
1
bitnamilegacy/kube-state-metrics:204a3044b384b
openssl@3.0.16-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
openssl@3.0.13-1~deb12u1
no fix listed
1
bitnamilegacy/mariadb:11.2.6-debian-12-r0373c3c260571
openssl@3.0.14-1~deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.