StackRadar

CVE-2026-73282

Medium

Advisory

Published 11 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
353
of 17,787 indexed, latest versions
Container images
336
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 353 of 17,787 indexed charts deploy, on 336 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+49 more1:8.9p1-3ubuntu0.17, 1:9.6p1-3ubuntu13.19, 1:10.2p1-2ubuntu3.6307
opensshapk10.3_p1-r010.3_p1-r129
OSV records
ALPINE-CVE-2026-73282DEBIAN-CVE-2026-73282UBUNTU-CVE-2026-73282
Also known as
USN-8721-1

Charts affected

353 by stars
ChartLatestAffected imagesRadar Score
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-73282.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
openssh@10.3_p1-r0
10.3_p1-r1

Open the chart page →

904
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-73282.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
no fix listed

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-73282.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.17

Open the chart page →

14,100

Container images carrying it

336 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
openssh@1:9.2p1-2+deb12u4
no fix listed
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
openssh@1:8.2p1-4ubuntu0.5
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssh@1:9.2p1-2+deb12u4
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
openssh@1:9.2p1-2+deb12u10
no fix listed
1
ghcr.io/silverbulletmd/silverbullet:2.10.027b5724cc367
openssh@10.3_p1-r0
10.3_p1-r1
1
ghcr.io/stac-utils/stac-fastapi-pgstac:6.4.0fa35b9519abb
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.17
1
ghcr.io/wgbh-mla/chowda:main86ab9effd1a5
openssh@1:10.0p1-7+deb13u4
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
openssh@1:9.2p1-2+deb12u7
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
openssh@1:9.2p1-2+deb12u1
no fix listed
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
openssh@1:9.2p1-2+deb12u4
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssh@1:9.2p1-2+deb12u3
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssh@1:9.2p1-2+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
openssh@1:9.2p1-2+deb12u3
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
openssh@1:9.2p1-2+deb12u2
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
openssh@1:9.2p1-2+deb12u1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
openssh@1:8.2p1-4ubuntu0.2
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.17
1
quay.io/aerokube/keygen:1.0.1578934444f04
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.17
1
quay.io/argoproj/argocd:v3.5.10deb1a1c9176
openssh@1:10.2p1-2ubuntu3.5
1:10.2p1-2ubuntu3.6
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
openssh@1:8.9p1-3
1:8.9p1-3ubuntu0.17
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssh@1:9.6p1-3ubuntu13.11
1:9.6p1-3ubuntu13.19
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssh@1:9.6p1-3ubuntu13.13
1:9.6p1-3ubuntu13.19
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.17
1
quay.io/argoprojlabs/gitops-promoter:v0.38.19c8a510dc25e
openssh@1:10.0p1-7+deb13u4
no fix listed
1
quay.io/codefresh/dind:3.0.250885ab519dac
openssh@10.3_p1-r0
10.3_p1-r1
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssh@1:7.2p2-4ubuntu2.10
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
openssh@1:9.2p1-2+deb12u10
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssh@1:10.0p1-7
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssh@1:9.2p1-2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.