StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3,047
of 17,805 indexed, latest versions
Container images
3,315
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 3,047 of 17,805 indexed charts deploy, on 3,315 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+60 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,845
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,439
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+3 moreno fix listed11
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-620
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

3,047 by stars
ChartLatestAffected imagesRadar Score
clickhousehelmforgeVerified publisher2.0.21 of 1See more

clickhouse helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.8.3d73903d1b61d
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,625
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/mongo:8.3.85211c51171f5
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

69,307
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,428
dawarichhelmforgeVerified publisher1.0.12 of 4See more

dawarich helmforge 1.0.1

2 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
postgis/postgis:18-3.67e00e8c3539f
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

10,542
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
openssl@3.5.4-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

30,389
druidhelmforgeVerified publisher1.3.62 of 4See more

druid helmforge 1.3.6

2 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/zookeeper:3.9.5f258365d4882
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

8,730
drupalhelmforgeVerified publisher1.2.131 of 2See more

drupal helmforge 1.2.13

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

3,921
entehelmforgeVerified publisher1.0.23 of 4See more

ente helmforge 1.0.2

3 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/ente/server:0472c929b6070e61fecaf2013d47efce2dcda462f646b68a1b8d
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

4,321
fastmcp-serverhelmforgeVerified publisher1.7.41 of 1See more

fastmcp-server helmforge 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.11.2fcb7017327d6
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,359
giteahelmforgeVerified publisher1.1.201 of 1See more

gitea helmforge 1.1.20

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
gitea/gitea:1.27.3-rootless1c17ecaead42
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

543
github-mcp-serverhelmforgeVerified publisher1.0.31 of 1See more

github-mcp-server helmforge 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/github/github-mcp-server:v1.9.0881b53d6f75f
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

413
glancehelmforgeVerified publisher1.0.01 of 1See more

glance helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
glanceapp/glance:v0.8.69dfb09470b20
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

153
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,142
immichhelmforgeVerified publisher1.2.84 of 5See more

immich helmforge 1.2.8

4 of the 5 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
openssl@3.0.20-1~deb12u2
no fix listed
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

11,268
jupyterhubhelmforgeVerified publisher1.0.63 of 3See more

jupyterhub helmforge 1.0.6

3 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
curlimages/curl:8.21.07c12af72ceb3
openssl@3.5.7-r0
3.5.8-r0
jupyterhub/configurable-http-proxy:5.3.069a7170eeeda
openssl@3.5.7-r0
3.5.8-r0
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
openssl@3.0.19-1~deb12u2
no fix listed

Open the chart page →

5,541
komgahelmforgeVerified publisher1.4.151 of 1See more

komga helmforge 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

29,969
listmonkhelmforgeVerified publisher1.1.143 of 3See more

listmonk helmforge 1.1.14

3 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:17-alpine18cfe3ef5e68
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
listmonk/listmonk:v6.2.0f535d59e1499
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,900
mcp-serverhelmforgeVerified publisher1.0.01 of 1See more

mcp-server helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
helmforge/fastmcp-server:0.2.061f759a1421f
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

3,508
medikeephelmforgeVerified publisher2.0.12 of 3See more

medikeep helmforge 2.0.1

2 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/afairgiant/medikeep:v0.70.04c28334f3c79
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,497
memcachedhelmforgeVerified publisher1.0.81 of 1See more

memcached helmforge 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,100
memoshelmforgeVerified publisher2.0.02 of 2See more

memos helmforge 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
openssl@3.5.7-r0
3.5.8-r0
neosmemo/memos:0.30.071a5b4738d1b
openssl@3.3.7-r0
3.3.7-r1

Open the chart page →

944
metabasehelmforgeVerified publisher1.2.291 of 3See more

metabase helmforge 1.2.29

1 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,713
middlewarehelmforgeVerified publisher1.2.63 of 4See more

middleware helmforge 1.2.6

3 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
middlewareeng/middleware:0.3.1747d880812f1
openssl@3.0.16-1~deb12u1
no fix listed

Open the chart page →

9,861
moodlehelmforgeVerified publisher1.1.02 of 2See more

moodle helmforge 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

6,363
mosquittohelmforgeVerified publisher1.5.01 of 1See more

mosquitto helmforge 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/eclipse-mosquitto:2.0.22212f89e1eaeb
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
netboxhelmforgeVerified publisher2.0.13 of 4See more

netbox helmforge 2.0.1

3 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.4

Open the chart page →

4,439
ntfyhelmforgeVerified publisher1.2.21 of 1See more

ntfy helmforge 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.28.06ef4b819f722
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

165
opencloudhelmforgeVerified publisher1.0.01 of 1See more

opencloud helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
opencloudeu/opencloud:7.2.46d992ccc5f1c
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

678
opencuthelmforgeVerified publisher1.1.93 of 5See more

opencut helmforge 1.1.9

3 of the 5 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
helmforge/opencut:v0.3.0bf11156e0ab5
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,837
openreel-videohelmforgeVerified publisher1.0.31 of 1See more

openreel-video helmforge 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
helmforge/openreel-video:v0.5.07ba0d47b943f
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,081
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,601
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
openssl@3.5.1-1
3.5.7-1~deb13u2

Open the chart page →

4,867
pimcorehelmforgeVerified publisher2.0.13 of 6See more

pimcore helmforge 2.0.1

3 of the 6 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
dunglas/mercure:v0.24.2916834e49961
openssl@3.5.6-r0
3.5.8-r0
library/mariadb:12.3.3dd9b303aed4f
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
library/rabbitmq:4.3.5-alpine3486d98205df
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,238
pocket-idhelmforgeVerified publisher1.0.02 of 2See more

pocket-id helmforge 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/node:24.21.0-alpine3.23159fe6464903
openssl@3.5.7-r0
3.5.8-r0
ghcr.io/pocket-id/pocket-id:v2.14.001540977dcf4
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

465
rabbitmqhelmforgeVerified publisher1.7.11 of 1See more

rabbitmq helmforge 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.5-alpine3486d98205df
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
reactive-resumehelmforgeVerified publisher1.0.02 of 4See more

reactive-resume helmforge 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,136
ryothelmforgeVerified publisher1.0.02 of 2See more

ryot helmforge 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

6,138
siyuanhelmforgeVerified publisher1.0.01 of 1See more

siyuan helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
b3log/siyuan:v3.8.36ab17ed3ca40
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

175
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,133
strava-statisticshelmforgeVerified publisher1.1.161 of 2See more

strava-statistics helmforge 1.1.16

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
robiningelbrecht/strava-statistics:v5.0.040842cdfd616
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

863
supersethelmforgeVerified publisher1.3.64 of 5See more

superset helmforge 1.3.6

4 of the 5 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
openssl@3.0.20-1~deb12u2
no fix listed
helmforge/kubectl:1.35.3c3f97e954c47
openssl@3.5.5-r0
3.5.8-r0
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

5,870
text-embeddings-inferencehelmforgeVerified publisher1.0.01 of 2See more

text-embeddings-inference helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.9.3ad950d30878e
openssl@3.0.18-1~deb12u2
no fix listed

Open the chart page →

2,597
tomcathelmforgeVerified publisher1.0.61 of 2See more

tomcat helmforge 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/tomcat:11.0.25-jdk17-temurin-noble9e1d2afa6898
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

1,306
twentyhelmforgeVerified publisher1.0.13 of 5See more

twenty helmforge 1.0.1

3 of the 5 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/node:24.21.0-alpinebe80f76cf40e
openssl@3.5.7-r0
3.5.8-r0
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:8.10.1298e5b3bc566
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,717
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:18.6-trixie4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

2,821
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5f258365d4882
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

3,158
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
openssl@3.0.11-1~deb12u2
no fix listed

Open the chart page →

12,717
jellyfinhelm-l3st86Verified publisher0.1.81 of 1See more

jellyfin helm-l3st86 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
jellyfin/jellyfin:latestaefb67e6a7ff
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2

Open the chart page →

2,658
openaevhelm-openbasVerified publisher2.0.54 of 7See more

openaev helm-openbas 2.0.5

4 of the 7 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
openssl@3.0.16-1~deb12u1
no fix listed
openaev/platform:3.260904.00a12ce8b3db9
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15
rustfs/rustfs:1.0.0-beta.1241fe89380f41
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

7,607
openbashelm-openbasVerified publisher1.8.144 of 7See more

openbas helm-openbas 1.8.14

4 of the 7 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
openssl@3.0.17-1~deb12u2
no fix listed
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
openssl@3.0.16-1~deb12u1
no fix listed
openbas/caldera-server:5.1.0a277796d9724
openssl@3.0.15-1~deb12u1
no fix listed
openbas/platform:2.0.5d986d80b0a75
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.15

Open the chart page →

25,395

Container images carrying it

3,315 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dysnix/docker-bitcoind:0.29.0490ca8e3dd21
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.15
1
ghcr.io/dysnix/docker-tiny:0.0.16b8e02430649
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/edgelesssys/marblerun/coordinator:v1.9.2e589db0d0a2c
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/elastiflow/mermin:v0.4.1205053c8a3e2
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/element-hq/matrix-authentication-service:0.14.0834ea54370f0
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
openssl@3.0.13-1~deb12u1
no fix listed
1
ghcr.io/elk-zone/elk:main046dfdb8550c
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/eminaktas/oom-tracer:v0.1.0c90ca8389c87
openssl@3.5.1-r0
3.5.8-r0
1
ghcr.io/emissary-ingress/emissary:4.1.04a981156abee
openssl@3.0.20-1~deb12u1
no fix listed
1
ghcr.io/ente/server:0472c929b6070e61fecaf2013d47efce2dcda462f646b68a1b8d
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/ente/web:5ab0c5b4c7a89c4e470ef6f793600da33cebf35d3f4864eb7f11
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/erikmagkekse/btrfs-nfs-csi:0.12.0cb29d9b801a5
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/erlkoenig91/prompt-db-backend:1.0.7ab120359810d
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/esomore/bitcoin-prometheus-exporter:masterded173632986
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/esphome/esphome:latest000c5ee5ee96
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/ethpandaops/benchmarkoor:latest5470b2ec3161
openssl@3.3.6-r0
3.3.7-r1
1
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/ethpandaops/dispatchoor-api:latesta0b272f6682a
openssl@3.3.6-r0
3.3.7-r1
1
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/ethpandaops/syncoor-web:master60d7c38d6062
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.4.00f4a5c0eea07
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/ferriskey/ferriskey-api:0.8.07b479fc31340
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/ferriskey/ferriskey-webapp:0.8.081d62c161732
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
openssl@3.0.17-1~deb12u3
no fix listed
1
ghcr.io/flannel-io/flannel:v0.28.9708a2c9c1cfb
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/flannel-io/flannel-cni-plugin:v1.9.1-flannel39fccdf677e6e
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
openssl@3.0.17-1~deb12u2
no fix listed
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/fluxcd/flagger:1.45.015b372d35012
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/fluxcd/image-automation-controller:v1.2.26b0b16ab2115
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fluxcd/image-reflector-controller:v1.2.227e6bad1dac5
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fluxcd/kustomize-controller:v1.9.23aecec8bafdb
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fluxcd/notification-controller:v1.9.29ce503e7bcb8
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.