StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,968
of 17,821 indexed, latest versions
Container images
3,334
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 2,968 of 17,821 indexed charts deploy, on 3,334 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+59 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,878
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,425
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-614
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

2,968 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

3,334 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/vinny1892/octantis:latest45459c0910fc
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/voidmind-io/voidllm:0.0.250df11dd20c28
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
openssl@3.3.6-r0
3.3.7-r1
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.29
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.29
1
ghcr.io/voyagermesh/crd-manager:v0.1.013fd0cccafe8
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
openssl@3.0.9-1
no fix listed
1
ghcr.io/vvanouytsel/jetspotter:1.48.1ec0e17a94f61
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
openssl@3.5.4-r0
3.5.8-r0
1
ghcr.io/wearefrank/frank-gateway:1.0.05ccf797ccdf1
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.15
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/wenisch-tech/chronoreaper:1.1.10447726cec07b
openssl@3.5.6-r0
3.5.8-r0
1
ghcr.io/wez/govee2mqtt:2026.03.25-ab9deb66a9d9fe330574
openssl@3.0.18-1~deb12u2
no fix listed
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
openssl@3.5.0-r0
3.5.8-r0
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
openssl@3.0.18-1~deb12u1
no fix listed
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/wiremind/ovh-exporter:v2.3.1609f955bd977
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/wjentner/k8s-db-backup-retention:v1.1.08027bb46d1f4
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoconnect:1.84.285f93ced88b2
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/wrenix/autopush-rs/autoendpoint:1.84.2d95e9a124eed
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/router:0.243.05afcab98d9d7
openssl@3.0.17-1~deb12u2
no fix listed
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
3.5.7-1~deb13u2
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
openssl@3.0.19-1~deb12u2
no fix listed
1
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
openssl@3.3.2-r4
3.3.7-r1
1
ghcr.io/zalando/postgres-operator:v2.0.275f69eac43ac
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/zalando/skipper:v0.27.883a357a2a4bef
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/zapier/kubechecks:latest60cea46ce830
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/zazuko/fuseki-geosparql:v5.2.06fbd8983f750
openssl@3.5.7-r0
3.5.8-r0
1
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u2
1
ghcr.io/zokeber/velero-notifications:0.0.176d84f6c4ce20
openssl@3.5.5-r0
3.5.8-r0
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.