StackRadar

CVE-2026-73281

Low

Advisory

Published 11 Aug 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.5
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
359
of 17,781 indexed, latest versions
Container images
342
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 359 of 17,781 indexed charts deploy, on 342 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+49 more1:8.9p1-3ubuntu0.17, 1:9.6p1-3ubuntu13.19, 1:10.2p1-2ubuntu3.6313
opensshapk10.3_p1-r010.3_p1-r129
OSV records
ALPINE-CVE-2026-73281DEBIAN-CVE-2026-73281UBUNTU-CVE-2026-73281
Also known as
USN-8721-1

Charts affected

359 by stars
ChartLatestAffected imagesRadar Score
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssh@1:10.0p1-7+deb13u4
no fix listed

Open the chart page →

4,423
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
no fix listed

Open the chart page →

14,358
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.19

Open the chart page →

4,305
jenkinswebencryptor1.9.181 of 1See more

jenkins webencryptor 1.9.18

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
openssh@1:10.0p1-7+deb13u4
no fix listed

Open the chart page →

2,476
argocd-image-updaterwenerme1.3.11 of 1See more

argocd-image-updater wenerme 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-image-updater:v1.3.0cb009167015c
openssh@10.3_p1-r0
10.3_p1-r1

Open the chart page →

718
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
openssh@10.3_p1-r0
10.3_p1-r1

Open the chart page →

904
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-73281.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.17

Open the chart page →

14,100

Container images carrying it

342 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
antiantiops/vscode-browser-docker:1.137.0eeff80a99d92
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
apache/airflow:2.8.4-python3.964e58748b6b9
openssh@1:9.2p1-2+deb12u2
no fix listed
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
openssh@1:9.2p1-2+deb12u3
no fix listed
1
apache/airflow:2.8.1e5560ad0b86e
openssh@1:9.2p1-2+deb12u2
no fix listed
1
apache/answer:2.0.2a0d71b0e30a5
openssh@10.3_p1-r0
10.3_p1-r1
1
apache/hertzbeat:1.8.075d48a62748f
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.19
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
openssh@1:9.6p1-3ubuntu13.14
1:9.6p1-3ubuntu13.19
1
apache/ranger:2.7.076c176e8a0e4
openssh@1:8.9p1-3ubuntu0.13
1:8.9p1-3ubuntu0.17
1
aristidetm/basic-notebook:3.6.5469dbc951224
openssh@1:9.2p1-2+deb12u3
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssh@1:9.2p1-2+deb12u2
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
openssh@1:9.6p1-3ubuntu13.13
1:9.6p1-3ubuntu13.19
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
openssh@1:9.2p1-2
no fix listed
1
atlassian/bamboo:12.1.114af4bb6c8d46
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
openssh@1:9.6p1-3ubuntu13.19
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
openssh@1:9.2p1-2
no fix listed
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
openssh@1:10.0p1-7+deb13u4
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
openssh@1:10.0p1-7
no fix listed
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
openssh@1:9.2p1-2+deb12u6
no fix listed
1
bitnamilegacy/git:latest4b08d0c5af8d
openssh@1:9.2p1-2+deb12u6
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
openssh@1:9.2p1-2+deb12u4
no fix listed
1
bnjbvr/kresus:0.22.137e216b182c8
openssh@1:9.2p1-2+deb12u3
no fix listed
1
calltelemetry/web:0.8.1-rc7205d13269e350
openssh@1:9.2p1-2+deb12u3
no fix listed
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
openssh@1:9.2p1-2+deb12u3
no fix listed
1
castopod/castopod:1.12.101fd37280cbb2
openssh@1:9.2p1-2+deb12u3
no fix listed
1
cccs/assemblyline-core:4.7.4.stable177c3c25d4d6e0
openssh@1:9.2p1-2+deb12u10
no fix listed
1
cccs/assemblyline-socketio:4.7.4.stable1724646dbfd944
openssh@1:9.2p1-2+deb12u10
no fix listed
1
cccs/assemblyline-ui:4.7.4.stable171a7a103668f5
openssh@1:9.2p1-2+deb12u10
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
openssh@1:8.9p1-3ubuntu0.15
1:8.9p1-3ubuntu0.17
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
openssh@1:6.6p1-2ubuntu2.13
no fix listed
1
chetangautamm/repo:sipp.v3e7f7049e1544
openssh@1:8.2p1-4ubuntu0.1
no fix listed
1
cheveo/azp-agent:1.0.282240f890884
openssh@1:8.9p1-3ubuntu0.11
1:8.9p1-3ubuntu0.17
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
openssh@1:10.0p1-7+deb13u1
no fix listed
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
openssh@1:9.2p1-2+deb12u7
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
openssh@1:8.2p1-4ubuntu0.4
no fix listed
1
cribl/cribl:3.0.2762747cb6796
openssh@1:7.6p1-4ubuntu0.3
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
openssh@1:8.9p1-3ubuntu0.13
1:8.9p1-3ubuntu0.17
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.17
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
openssh@1:8.2p1-4ubuntu0.13
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
openssh@1:10.0p1-7
no fix listed
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
openssh@1:10.0p1-7+deb13u4
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
openssh@1:10.0p1-7+deb13u4
no fix listed
1
esphome/esphome:2026.8.285abea33854b
openssh@1:10.0p1-7+deb13u4
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
openssh@1:9.2p1-2+deb12u2
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
openssh@1:9.2p1-2+deb12u3
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
openssh@1:9.2p1-2+deb12u5
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
openssh@1:7.2p2-4ubuntu2.2
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
openssh@1:9.2p1-2+deb12u9
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
openssh@1:8.2p1-4ubuntu0.13
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
openssh@1:9.2p1-2+deb12u6
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.