StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,040
of 17,813 indexed, latest versions
Container images
3,367
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,040 of 17,813 indexed charts deploy, on 3,367 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+60 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,873
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,458
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-619
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

3,040 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,367 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
featurehub/mr:1.9.1477d8bf771a9
openssl@3.3.3-r0
3.3.7-r1
1
felipecs8/app-db-connection-test:v129e06c9c6385
openssl@3.0.15-1~deb12u1
no fix listed
1
felipecs8/conversor-temperatura:v1f945423be36d
openssl@3.3.3-r0
3.3.7-r1
1
felipecs8/landing-page:v1db6d44e325a1
openssl@3.5.1-r0
3.5.8-r0
1
ffutop/ddc-ph-kafka-egress:latest319d94c8481a
openssl@3.5.4-r0
3.5.8-r0
1
ffutop/ddc-ph-kafka-ingress:latest15832d4f19be
openssl@3.5.4-r0
3.5.8-r0
1
ffutop/ddc-transport-udp-receive:latest651ca530d787
openssl@3.5.4-r0
3.5.8-r0
1
ffutop/ddc-transport-udp-send:latest4222eb5ee847
openssl@3.5.4-r0
3.5.8-r0
1
filebrowser/filebrowser:v2.63.15-s6dbac07403040
openssl@3.5.7-r0
3.5.8-r0
1
filegator/filegator:latest34bf565a11a4
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
filiparag/hetzner_ddns:1.0.15a9cbae7997c
openssl@3.5.4-r0
3.5.8-r0
1
firefart/requesttracker:5.0.40d6249906d8c
openssl@3.0.11-1~deb12u1
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
openssl@3.0.16-1~deb12u1
no fix listed
1
flanksource/apm-hub:v0.0.471dacc3195bf9
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
flanksource/batch-runner:v1.0.44689687a7cf95
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
flashcatcloud/nightingale:8.5.1421acb36181b
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2
1
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
openssl@3.0.16-1~deb12u1
no fix listed
1
fleetdm/fleet:v4.66.012e644b7f40e
openssl@3.3.3-r0
3.3.7-r1
1
fluent/fluent-bit:4.2.6a52221a2a3eb
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
fluent/fluent-bit:5.1.1a941bdd5ca55
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
fluent/fluent-bit:4.0.4ca08b7d2df5b
openssl@3.0.16-1~deb12u1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
openssl@3.0.17-1~deb12u3
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
fnzv/dump1090:latestb3079b95c336
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
foggbh/stocky:latest8b7a2e5ecf4e
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-caiasoft:latestc3cfa89eee2f
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-connexion:latestb4863d135524
openssl@3.5.6-r0
3.5.8-r0
1
folioci/edge-dematic:latest48c9b1d180d4
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-inn-reach:latestc64e4d9dd3fc
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-ncip:lateste760dbb81d1a
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-oai-pmh:latesteedfcbc29792
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-orders:latest1ef654ee9f23
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-patron:latest682b852e056d
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-rtac:latest15ef73b1abd0
openssl@3.5.7-r0
3.5.8-r0
1
folioci/edge-sip2:latest86106f20ef51
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-authtoken:latest995a25a33133
openssl@3.5.5-r0
3.5.8-r0
1
folioci/mod-calendar:latest22f65982efd7
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-circulation-storage:latest6bdddcafbc0f
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-configuration:latestdd0cdc89670a
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-copycat:latest1513fad2b799
openssl@3.5.6-r0
3.5.8-r0
1
folioci/mod-courses:latest68ca414f5596
openssl@3.5.5-r0
3.5.8-r0
1
folioci/mod-data-export:latest0cc86bf09755
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-data-export-spring:latestf1d7caf4544b
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-ebsconet:latest3ae8cb99daa3
openssl@3.5.6-r0
3.5.8-r0
1
folioci/mod-email:latest79ea8e2e7ebf
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-entities-links:latest3e2412815c0f
openssl@3.5.7-r0
3.5.8-r0
1
folioci/mod-eusage-reports:latest15de67587091
openssl@3.5.6-r0
3.5.8-r0
1
folioci/mod-event-config:latest0192adad3897
openssl@3.5.7-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.