StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,968
of 17,821 indexed, latest versions
Container images
3,334
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 2,968 of 17,821 indexed charts deploy, on 3,334 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+59 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,878
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,425
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-614
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

2,968 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,334 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
zwavejs/zwave-js-ui:11.22.314d018bb689e
openssl@3.5.7-r0
3.5.8-r0
1
gcr.io/abacus-labs-dev/hyperlane-agent:10c0ab1-20231215-220639f33e88324a40
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
1
gcr.io/datadoghq/csi-driver:1.4.086c713de81d9
openssl@3.5.7-r0
3.5.8-r0
1
gcr.io/datadoghq/observability-pipelines-worker:2.21.1de6ff0f1a854
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
openssl@3.0.13-0ubuntu3.1
3.0.13-0ubuntu3.15
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.29
1
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
openssl@3.0.14-1~deb12u2
no fix listed
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
openssl@3.0.14-1~deb12u2
no fix listed
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
openssl@3.0.15-1~deb12u1
no fix listed
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
openssl@3.0.15-1~deb12u1
no fix listed
1
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/291-group/lan-orangutan:3.3.886b55c80eeb1
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/aardbol/opencode-server:v1.18.23-alpine7930061993f7
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/absmach/magistrala/ui-backend:latestb3986672fa02
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.15
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
openssl@3.0.13-0ubuntu3
3.0.13-0ubuntu3.15
1
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/aklivity/zilla:2.4.3e33d59dbb606
openssl@3.0.2-0ubuntu1.25
3.0.2-0ubuntu1.29
1
ghcr.io/akpw/mktxp:1.2.17bd6f22f7db0a
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/akpw/mktxp:1.2.20f894f2457670
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/alam00000/bentopdf-simple:2.8.5268f3e4a1aee
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/alam00000/bentopdf-simple:2.8.42bae644d2735
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/alekc/samba-docker:v1.1.0cc9a028d9c43
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/alethic/auth0-operator-image:1.4.122468990a8521
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
openssl@3.0.18-1~deb12u2
no fix listed
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/angelnu/pod-gateway:v1.13.0a5b032e15f75
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
openssl@3.0.14-1~deb12u2
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.29
1
ghcr.io/appscode/ace:v0.2.0b8e03da90e70
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/acerproxy:v0.2.021de3771fdd5
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/aceshifter:v0.0.3e5f5c254a55a
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/appscode/aws-credential-manager:v0.1.00511bbe501c3
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/azure-credential-manager:v0.1.0f5c797f7fbe7
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/appscode/b3:v2026.9.1178a9fb785ec5
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/appscode/catalog-manager:v0.13.0fc336c5b9655
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/cattleset:v0.0.145554a03e448
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/cert-manager-webhook-ace:v0.0.2dc6b5fdcec06
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/appscode/cluster-presets:v0.0.128fbdd2479645
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/cluster-ui:2.4.0f527d10769ac
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/appscode/csi-driver-cacerts:v0.6.0ab213b156017
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/appscode/external-dns-operator:v0.4.05605f97e636d
openssl@3.5.7-r0
3.5.8-r0
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.