StackRadar

CVE-2026-72897

High

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
929
of 17,957 indexed, latest versions
Container images
672
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 929 of 17,957 indexed charts deploy, on 672 images.

Affected packageAffected versionsFixed inImages
openssldeb3.5.1-1, 3.5.1-1+deb13u1, 3.5.4-1~deb13u1, 3.5.4-1~deb13u2+15 more3.5.5-1ubuntu3.6667
nodejsdeb16.14.2-deb-1nodesource1, 16.18.0-deb-1nodesource1, 20.11.1-1nodesource1, 20.15.0-1nodesource1+1 moreno fix listed5
OSV records
DEBIAN-CVE-2026-72897UBUNTU-CVE-2026-72897
Also known as
USN-8847-1
Trending
Rank 26 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

929 by stars
ChartLatestAffected imagesRadar Score
unlaunla0.10.01 of 3See more

unla unla 0.10.0

1 of the 3 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

9,416
uptime-platformuptime-platformVerified publisher0.1.31 of 3See more

uptime-platform uptime-platform 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
sashastudent/uptime-platform:latest37a82b4e598e
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

784
vaultwardenvaultwarden-helmVerified publisher1.2.71 of 2See more

vaultwarden vaultwarden-helm 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:18.4-system-trixie42708a75345b
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

2,045
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed

Open the chart page →

82,141
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
bugsink/bugsink:246fc01ffbd60
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

4,382
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

2,105
argus-test-envvk-helm-charts2.0.01 of 1See more

argus-test-env vk-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
postgresappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,390
redisappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

redisapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

692
voteappvoting-app-helm-charts-repoVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

7,816
postgresappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

postgresapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,390
redisappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

redisapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

692
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/postgres:latest86c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed
library/redis:latest718f745deb7d
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

7,816
voting-app-envvoting-example-with-env0.0.31 of 6See more

voting-app-env voting-example-with-env 0.0.3

1 of the 6 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
kerolosayman308/voting-app-env:examplevotingapp_vote29d99802f2d7
openssl@3.5.5-1~deb13u1
no fix listed

Open the chart page →

7,480
aih-scannerwallarmVerified publisher2.9.01 of 2See more

aih-scanner wallarm 2.9.0

1 of the 2 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.9.0b39795d50e83
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

3,118
wallarm-gatewaywallarmVerified publisher0.4.01 of 1See more

wallarm-gateway wallarm 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
wallarm/gateway-controller:0.4.09c6ed23e2f0e
openssl@3.5.6-1~deb13u1
no fix listed

Open the chart page →

2,202
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

2,766
argo-cdwener10.9.41 of 3See more

argo-cd wener 10.9.4

1 of the 3 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6

Open the chart page →

3,155
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/postgres:1886c951e05bf5
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

3,876
wordpress-alpinewordpress-alpine1.5.181 of 6See more

wordpress-alpine wordpress-alpine 1.5.18

1 of the 6 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/memcached:1.6.45dc561d52bb8a
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

4,491
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

4,986
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,991
dingtalk-botxxl-job-adminVerified publisher0.1.31 of 2See more

dingtalk-bot xxl-job-admin 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
openssl@3.5.4-1~deb13u1
no fix listed

Open the chart page →

3,457
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
no fix listed

Open the chart page →

1,484
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/nginx:stableb972f831f200
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765
jenkinszanise-jenkins-helm-chart0.1.01 of 1See more

jenkins zanise-jenkins-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

2,766
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
no fix listed

Open the chart page →

596
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-72897.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
no fix listed

Open the chart page →

1,765

Container images carrying it

672 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
openssl@3.5.1-1+deb13u1
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
openssl@3.5.5-1ubuntu3
3.5.5-1ubuntu3.6
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
openssl@3.5.4-1~deb13u2
no fix listed
1
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest3e0fbd0274eb
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/securo-finance/securo-backend:0.16.2b1cd83ff7828
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/sergelogvinov/proxmox-csi-node:v0.20.0e0151137a1c5
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
openssl@3.5.4-1~deb13u1
no fix listed
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/stac-utils/stac-fastapi-pgstac:7.0.08b026c47cc1b
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/steadybit/agent:2.4.6d246bfa55f63
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/steadybit/extension-container:v1.8.2a1ce3f58f354
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/steadybit/extension-host:v1.8.27c3a17d47cf4
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.9.162614fd45986
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/thm-mni-ii/fbs-core:v2.0.1b585ab8bb7e8
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
ghcr.io/thm-mni-ii/fbs-identity-service:v2.0.1baf79539e5df
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
openssl@3.5.5-1~deb13u2
no fix listed
1
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
openssl@3.5.5-1ubuntu3.2
3.5.5-1ubuntu3.6
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
openssl@3.5.5-1~deb13u1
no fix listed
1
ghcr.io/wekan/ferretdb:latest23c6f0596a80
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/wekan/wekan:v12.110c9b4e571cb9
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/wgbh-mla/chowda:maina63dadf119be
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/wittdennis/homeassistant-otbr:4.2.5282f840612d9
openssl@3.5.6-1~deb13u2
no fix listed
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
openssl@3.5.6-1~deb13u1
no fix listed
1
ghcr.io/yourls/yourls:1.10.62f2879125903
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/zammad/zammad:7.2.0-0011f7b62c718bce
openssl@3.5.7-1~deb13u2
no fix listed
1
ghcr.io/zeroclaw-labs/zeroclaw:v0.1.7497893753e16
openssl@3.5.4-1~deb13u2
no fix listed
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.72.6_local43316f900242
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
public.ecr.aws/aktosecurity/akto-api-security-mini-testing:1.74.4_local5bda14f66e8e
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
public.ecr.aws/aktosecurity/akto-threat-detection:1.16.2a47eb6cc17ea
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
public.ecr.aws/aktosecurity/akto-threat-detection:latesta728eb2eaf06
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
openssl@3.5.5-1~deb13u2
no fix listed
1
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
openssl@3.5.1-1
no fix listed
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
openssl@3.5.4-1~deb13u1
no fix listed
1
public.ecr.aws/jtekt-corporation/api-key-manager-gui:v0.1.10424fa47fbeb
openssl@3.5.7-1~deb13u2
no fix listed
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
quay.io/argoprojlabs/gitops-promoter:v0.42.0105b74aaf5e9
openssl@3.5.6-1~deb13u2
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
openssl@3.5.6-1~deb13u2
no fix listed
1
quay.io/isindir/sops-secrets-operator:0.21.27bba7083dfa0
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
quay.io/maxiv/pieeat:0.9.3099715479210
openssl@3.5.6-1~deb13u1
no fix listed
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.