StackRadar

CVE-2026-63076

High

Advisory

Published 25 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,999
of 17,813 indexed, latest versions
Container images
3,298
deployed by those charts
Fix available
3 of 4
affected packages

CVE-2026-63076 affecting package openssl for versions less than 3.3.7-6

Carried by container images the latest versions of 2,999 of 17,813 indexed charts deploy, on 3,298 images.

Affected packageAffected versionsFixed inImages
openssldeb3.0.2-0ubuntu1, 3.0.2-0ubuntu1.2, 3.0.2-0ubuntu1.5, 3.0.2-0ubuntu1.6+60 more3.0.2-0ubuntu1.29, 3.0.13-0ubuntu3.15, 3.5.5-1ubuntu3.4, 3.5.7-1~deb13u21,840
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+12 more3.3.7-r1, 3.5.8-r01,422
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed17
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl33.3.7-619
OSV records
ALPINE-CVE-2026-63076DEBIAN-CVE-2026-63076UBUNTU-CVE-2026-63076AZL-97941ECHO-b5fe-8a22-4e2a
Also known as
USN-8678-1

Charts affected

2,999 by stars
ChartLatestAffected imagesRadar Score
kuberay-dashboarddanchevVerified publisher0.0.51 of 1See more

kuberay-dashboard danchev 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

553
nvidia-gpu-exporterdanchevVerified publisher1.0.31 of 1See more

nvidia-gpu-exporter danchev 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
openssl@3.5.5-1ubuntu3.2
3.5.5-1ubuntu3.4

Open the chart page →

1,250
dapr-agentsdapr-agents-devVerified publisher0.1.58 of 31See more

dapr-agents dapr-agents-dev 0.1.5

8 of the 31 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
grafana/grafana:12.3.39e1e77ade304
openssl@3.5.5-r0
3.5.8-r0
kiwigrid/k8s-sidecar:1.30.98c06e1ba643a
openssl@3.5.1-r0
3.5.8-r0
library/memcached:1.6.39-alpinec8503d4491ed
openssl@3.5.4-r0
3.5.8-r0
library/redis:6.2143f7bfc2358
openssl@3.0.20-1~deb12u2
no fix listed
mcp/grafana:latest9362bcf6aa0e
openssl@3.0.20-1~deb12u2
no fix listed
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
openssl@3.5.6-r0
3.5.8-r0
redis/redisinsight:latestb5e19ee240ab
openssl@3.5.7-r0
3.5.8-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

22,721
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

3,665
dns-mesh-controllerdashdns2.0.81 of 2See more

dns-mesh-controller dashdns 2.0.8

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
emirozbir/dashdns-admission-webhook:v2.0.56801ba2a3fc3
openssl@3.5.5-r0
3.5.8-r0

Open the chart page →

1,111
dash-opsdash-ops0.0.41 of 1See more

dash-ops dash-ops 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
dashops/dash-ops:latest23537693ff05
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

509
dask-gatewaydask2026.3.01 of 2See more

dask-gateway dask 2026.3.0

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/traefik:3.3.5104204dadedf
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

2,165
metabasedasmeta0.1.01 of 1See more

metabase dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
metabase/metabase:v0.63.1.124f150effd484
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

803
pgcatdasmeta0.1.31 of 2See more

pgcat dasmeta 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
openssl@3.0.13-1~deb12u1
no fix listed

Open the chart page →

3,192
proxysqldasmeta1.2.31 of 1See more

proxysql dasmeta 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
proxysql/proxysql:2.7.3a4d6c35c2949
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

2,912
redashdasmeta0.1.01 of 1See more

redash dasmeta 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
redash/redash:26.3.0c5c9148f5c38
openssl@3.0.18-1~deb12u2
no fix listed

Open the chart page →

5,214
sentry-relaydasmeta0.1.21 of 1See more

sentry-relay dasmeta 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
getsentry/relay:24.10.0ba7bf9163219
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

3,621
monitoring-stackdata354-helmVerified publisher1.4.22 of 4See more

monitoring-stack data354-helm 1.4.2

2 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
grafana/fluent-plugin-loki:latest8a3882e8c28b
openssl@3.0.16-1~deb12u1
no fix listed
grafana/grafana:latestf772d434e8fa
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

3,295
datacube-dashboarddatacube-charts0.5.101 of 2See more

datacube-dashboard datacube-charts 0.5.10

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2

Open the chart page →

1,688
datacube-indexdatacube-charts0.4.42 of 2See more

datacube-index datacube-charts 0.4.4

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
opendatacube/ows:latest668cbb41473c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

6,234
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

6,085
datacube-processingdatacube-charts0.1.11 of 2See more

datacube-processing datacube-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

93,053
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.29

Open the chart page →

6,281
cloudpremdatadogVerified publisher0.5.21 of 1See more

cloudprem datadog 0.5.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
public.ecr.aws/datadog/cloudprem:v0.1.33bda08753668d
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

1,192
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
gcr.io/datadoghq/csi-driver:1.4.086c713de81d9
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,056
observability-pipelines-workerdatadogVerified publisher2.21.21 of 1See more

observability-pipelines-worker datadog 2.21.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
gcr.io/datadoghq/observability-pipelines-worker:2.21.1de6ff0f1a854
openssl@3.0.13-0ubuntu3.12
3.0.13-0ubuntu3.15

Open the chart page →

860
private-action-runnerdatadogVerified publisher1.28.11 of 1See more

private-action-runner datadog 1.28.1

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
gcr.io/datadoghq/private-action-runner:v1.21.05f5918f843a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.15

Open the chart page →

2,190
datagrokdatagrok1.0.33 of 7See more

datagrok datagrok 1.0.3

3 of the 7 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
datagrok/grok_connect:latestf5876d3aebb8
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29
datagrok/grok_spawner:latest8c2d48c1545c
openssl@3.5.7-r0
3.5.8-r0
library/alpine:latest28bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,429
datagrok_grok_connectdatagrok1.0.01 of 1See more

datagrok_grok_connect datagrok 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
datagrok/grok_connect:latestf5876d3aebb8
openssl@3.0.2-0ubuntu1.26
3.0.2-0ubuntu1.29

Open the chart page →

1,688
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
openssl@3.0.15-1~deb12u1
no fix listed

Open the chart page →

10,156
dbgatedbgate-helm-chartVerified publisher0.1.81 of 1See more

dbgate dbgate-helm-chart 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
dbgate/dbgate:7.2.3f2dc7423ea88
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

1,449
decisionrules-aksdecisionrules-aksVerified publisher0.2.02 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
decisionrules/client:latest92e459f2c673
openssl@3.5.7-r0
3.5.8-r0
decisionrules/server:latestf38d8571fa06
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,141
decisionrules-eksdecisionrules-eksVerified publisher0.3.02 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
decisionrules/client:latest92e459f2c673
openssl@3.5.7-r0
3.5.8-r0
decisionrules/server:latestf38d8571fa06
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,141
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.02 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
decisionrules/client:latest92e459f2c673
openssl@3.5.7-r0
3.5.8-r0
decisionrules/server:latestf38d8571fa06
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

1,141
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.04 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

4 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
decisionrules/ai-engine:latest38c377e7c01e
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
decisionrules/business-intelligence:latest1135a6d4f09b
openssl@3.5.7-r0
3.5.8-r0
decisionrules/client:latest-rootless8c5e14b74a8b
openssl@3.5.7-r0
3.5.8-r0
decisionrules/server:latestf38d8571fa06
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

2,757
intel-gpu-exporterdefault-ghVerified publisher0.1.01 of 1See more

intel-gpu-exporter default-gh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.29

Open the chart page →

4,884
isponsorblocktvdefault-ghVerified publisher1.0.51 of 1See more

isponsorblocktv default-gh 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/dmunozv04/isponsorblocktv:v2.9.05b8cfa805cb6
openssl@3.3.5-r0
3.3.7-r1

Open the chart page →

692
jackettdefault-ghVerified publisher1.3.01 of 1See more

jackett default-gh 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
linuxserver/jackett:0.24.20929bca08e2e6f1
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

499
bentopdfdeimosfr-charts1.0.191 of 1See more

bentopdf deimosfr-charts 1.0.19

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/alam00000/bentopdf:2.8.86ef493c8e3bd
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

149
csi-driver-smbdeimosfr-charts1.20.31 of 5See more

csi-driver-smb deimosfr-charts 1.20.3

1 of the 5 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

3,022
linkdingdeimosfr-charts1.0.31 of 1See more

linkding deimosfr-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.35.00c5dddf0b37c
openssl@3.0.14-1~deb12u2
no fix listed

Open the chart page →

6,141
technitiumdeimosfr-charts15.4.01 of 1See more

technitium deimosfr-charts 15.4.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
technitium/dns-server:15.4.0df7d90ef0f7b
openssl@3.0.13-0ubuntu3.11
3.0.13-0ubuntu3.15

Open the chart page →

1,406
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,353
dell-fan-controllerdell-fan-controllerVerified publisher1.0.71 of 1See more

dell-fan-controller dell-fan-controller 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.15

Open the chart page →

2,587
challengedeneme0.1.02 of 2See more

challenge deneme 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u2
library/redis:6143f7bfc2358
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

2,788
deployhubdeployhubVerified publisher10.0.4152 of 11See more

deployhub deployhub 10.0.415

2 of the 11 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
openssl@3.5.4-r0
3.5.8-r0
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

11,342
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
openssl@3.5.4-r0
3.5.8-r0

Open the chart page →

2,535
clamav-apidevhatVerified publisher1.0.11 of 1See more

clamav-api devhat 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
ghcr.io/devhatro/clamav-api:1.0.2ff0cd9db78d3
openssl@3.3.2-r4
3.3.7-r1

Open the chart page →

2,246
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,268
frontend-servicedev-krishan-dhaka-charts1.0.21 of 1See more

frontend-service dev-krishan-dhaka-charts 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
devkrishan001/frontend:latesta0ad60836e6b
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

1,033
postgresdev-krishan-dhaka-charts1.0.21 of 1See more

postgres dev-krishan-dhaka-charts 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/postgres:15-alpinefe0737ba566a
openssl@3.5.7-r0
3.5.8-r0

Open the chart page →

494
devnopesdevnopes0.1.81 of 1See more

devnopes devnopes 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
sokushinbutsu/devnopes:latest0bbd90448671
openssl@3.5.6-r0
3.5.8-r0

Open the chart page →

463
apachedevops0.1.03 of 4See more

apache devops 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29
ghcr.io/codingducksrl/laravel:8.15be52524664c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

115,985
laraveldevops0.10.33 of 4See more

laravel devops 0.10.3

3 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mariadb:10.9.4fbb8456ebdb1
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.29
ghcr.io/codingducksrl/laravel:8.15be52524664c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

114,986
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2026-63076.

Container imageDigestPackageFixed in
library/alpine:328bd5fe8b56d
openssl@3.5.7-r0
3.5.8-r0
library/mariadb:10.8.30abf60f81588
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.29

Open the chart page →

13,065

Container images carrying it

3,298 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

No deployed image carries CVE-2026-63076.

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.