StackRadar

CVE-2026-75595

Critical

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
562
of 17,787 indexed, latest versions
Container images
631
deployed by those charts
Fix available
1 of 1
affected package

Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

Carried by container images the latest versions of 562 of 17,787 indexed charts deploy, on 631 images.

Affected packageAffected versionsFixed inImages
netty-handlermaven4.0.23.Final, 4.0.27.Final, 4.0.36.Final, 4.0.37.Final+102 more4.1.137.Final, 4.2.17.Final631
OSV records
GHSA-c4c3-7fpv-j4q5
Trending
Rank 12 in indexed charts, since 9 Sept 2026. See the ranking →

Charts affected

562 by stars
ChartLatestAffected imagesRadar Score
cp-cmfopenshift2.4.11 of 1See more

cp-cmf openshift 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
confluentinc/cp-cmf:2.4.1f466f8649aa8
netty-handler@4.2.16.Final
4.2.17.Final

Open the chart page →

179
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
netty-handler@4.1.119.Final
4.1.137.Final

Open the chart page →

7,792
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

13,100
openshift-integration-operatoropenshift-integration-operatorVerified publisher0.8.21 of 2See more

openshift-integration-operator openshift-integration-operator 0.8.2

1 of the 2 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
netty-handler@4.1.133.Final
4.1.137.Final

Open the chart page →

2,045
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
netty-handler@4.1.45.Final
4.1.137.Final

Open the chart page →

36,215
trinoopstty0.2.141See more

trino opstty 0.2.14

1 container image this version deploys carries CVE-2026-75595.

Container imageDigestPackageFixed in
trinodb/trino:4815b5e0a97f599
netty-handler@4.2.12.Final
4.2.17.Final

Open the chart page →

dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
netty-handler@4.1.106.Final
4.1.137.Final

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
netty-handler@4.1.118.Final
4.1.137.Final

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
netty-handler@4.1.109.Final
4.1.137.Final

Open the chart page →

1,753
p4p40.1.03 of 7See more

p4 p4 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
netty-handler@4.1.85.Final
4.1.137.Final
mastercloudapps/planner:v1.2340a950b311b2
netty-handler@4.1.42.Final
4.1.137.Final
mastercloudapps/server:v2.23f3d24dfe2686
netty-handler@4.1.82.Final
4.1.137.Final

Open the chart page →

27,537
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
netty-handler@4.1.42.Final
4.1.137.Final

Open the chart page →

19,720
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
netty-handler@4.1.111.Final
4.1.137.Final

Open the chart page →

2,097
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
netty-handler@4.1.56.Final
4.1.137.Final

Open the chart page →

6,237
Practica_4_helmpr04helm0.1.03 of 7See more

Practica_4_helm pr04helm 0.1.0

3 of the 7 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
netty-handler@4.1.82.Final
4.1.137.Final
codeurjc/toposervice:v1.09fb4c11e6a49
netty-handler@4.1.85.Final
4.1.137.Final
pcarrascoponce/planner:v1.0981fc482442c
netty-handler@4.1.70.Final
4.1.137.Final

Open the chart page →

27,558
practica-helmpractica-helm0.1.02 of 7See more

practica-helm practica-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
slagattollas/planner-practica:latestcecd95e31486
netty-handler@4.1.54.Final
4.1.137.Final
slagattollas/toposervice-practica:latestdc63973dae0d
netty-handler@4.1.54.Final
4.1.137.Final

Open the chart page →

28,484
hive-metastorepresto-loadbalancer0.2.31 of 1See more

hive-metastore presto-loadbalancer 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
datappeal/hive-metastore:lateste38c085a3567
netty-handler@4.1.17.Final
4.1.137.Final

Open the chart page →

9,606
trinopresto-loadbalancer0.2.101 of 2See more

trino presto-loadbalancer 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
trinodb/trino:4796af989b0846d
netty-handler@4.2.7.Final
4.2.17.Final

Open the chart page →

2,264
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
netty-handler@4.1.77.Final
4.1.137.Final

Open the chart page →

1,995
cadencequench-cadenceVerified publisher0.0.101 of 2See more

cadence quench-cadence 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/cassandradigest-pinned688f215f101f
netty-handler@4.1.136.Final
4.1.137.Final

Open the chart page →

132
cassandraquench-cassandraVerified publisher0.0.191 of 1See more

cassandra quench-cassandra 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/cassandradigest-pinned688f215f101f
netty-handler@4.1.136.Final
4.1.137.Final

Open the chart page →

50
identity-stackquench-identity-stackVerified publisher0.0.131 of 3See more

identity-stack quench-identity-stack 0.0.13

1 of the 3 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/keycloakdigest-pinned7e9bd0bbbb31
netty-handler@4.1.136.Final
4.1.137.Final

Open the chart page →

189
keycloakquench-keycloakVerified publisher0.0.231 of 2See more

keycloak quench-keycloak 0.0.23

1 of the 2 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/keycloakdigest-pinned7e9bd0bbbb31
netty-handler@4.1.136.Final
4.1.137.Final

Open the chart page →

142
neo4jquench-neo4jVerified publisher0.0.151 of 1See more

neo4j quench-neo4j 0.0.15

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/neo4jdigest-pinnedc07746a9527c
netty-handler@4.2.16.Final
4.2.17.Final

Open the chart page →

50
opensearchquench-opensearchVerified publisher0.1.51 of 1See more

opensearch quench-opensearch 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/opensearchdigest-pinned45c60f2fc239
netty-handler@4.2.16.Final
4.2.17.Final

Open the chart page →

50
pulsarquench-pulsarVerified publisher0.0.171 of 1See more

pulsar quench-pulsar 0.0.17

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/pulsardigest-pinnedc7b697c99af7
netty-handler@4.1.136.Final
4.1.137.Final

Open the chart page →

50
solrquench-solrVerified publisher0.0.141 of 1See more

solr quench-solr 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/solrdigest-pinned640585e8eb5c
netty-handler@4.2.16.Final
4.2.17.Final

Open the chart page →

75
zookeeperquench-zookeeperVerified publisher0.0.141 of 1See more

zookeeper quench-zookeeper 0.0.14

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/zookeeperdigest-pinneddf2b3e0adced
netty-handler@4.1.136.Final
4.1.137.Final

Open the chart page →

50
rada-platformrada-platform0.1.02 of 7See more

rada-platform rada-platform 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
netty-handler@4.1.87.Final
4.1.137.Final
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
netty-handler@4.1.108.Final
4.1.137.Final

Open the chart page →

21,211
mockserverradar-baseVerified publisher5.15.01 of 1See more

mockserver radar-base 5.15.0

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
netty-handler@4.1.86.Final
4.1.137.Final

Open the chart page →

1,257
radar-cp-ksql-serverradar-baseVerified publisher0.0.21 of 2See more

radar-cp-ksql-server radar-base 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
netty-handler@4.1.100.Final
4.1.137.Final

Open the chart page →

5,269
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
netty-handler@4.1.118.Final
4.1.137.Final

Open the chart page →

4,219
radar-mockserverradar-baseVerified publisher0.1.31 of 1See more

radar-mockserver radar-base 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
mockserver/mockserver:mockserver-5.15.00f9ef78c9489
netty-handler@4.1.86.Final
4.1.137.Final

Open the chart page →

1,257
radar-outputradar-baseVerified publisher1.2.101 of 1See more

radar-output radar-base 1.2.10

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
netty-handler@4.2.10.Final
4.2.17.Final

Open the chart page →

2,465
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
netty-handler@4.1.118.Final
4.1.137.Final

Open the chart page →

1,951
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
netty-handler@4.1.75.Final
4.1.137.Final

Open the chart page →

15,520
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
netty-handler@4.1.73.Final
4.1.137.Final

Open the chart page →

2,583
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
netty-handler@4.1.73.Final
4.1.137.Final

Open the chart page →

2,600
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
netty-handler@4.1.107.Final
4.1.137.Final

Open the chart page →

4,203
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
reportportal/service-jobs:5.7.2dc166c58485a
netty-handler@4.1.59.Final
4.1.137.Final

Open the chart page →

25,737
routr-connectroutr0.4.32 of 10See more

routr-connect routr 0.4.3

2 of the 10 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
fonoster/routr-edgeport:2.13.6d08a8a574a50
netty-handler@4.1.79.Final
4.1.137.Final
fonoster/routr-requester:2.13.6e0c823506eb2
netty-handler@4.1.79.Final
4.1.137.Final

Open the chart page →

11,021
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
netty-handler@4.1.135.Final
4.1.137.Final

Open the chart page →

2,261
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
netty-handler@4.2.12.Final
4.2.17.Final

Open the chart page →

6,207
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
netty-handler@4.1.42.Final
4.1.137.Final

Open the chart page →

3,978
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
netty-handler@4.1.77.Final
4.1.137.Final

Open the chart page →

16,101
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-75595.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
netty-handler@4.1.77.Final
4.1.137.Final

Open the chart page →

8,033

Container images carrying it

631 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
netty-handler@4.1.89.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.009a381c715ab
netty-handler@4.1.111.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.60aae0de7fca8
netty-handler@4.1.135.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
netty-handler@4.1.111.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:24.0.34d6f22991266
netty-handler@4.1.107.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:23.0.34f72a5b0c076
netty-handler@4.1.100.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
netty-handler@4.1.124.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
netty-handler@4.1.82.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
netty-handler@4.1.130.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
netty-handler@4.1.128.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.6.39b0330756022
netty-handler@4.1.133.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.7.29d1f1b2b7261
netty-handler@4.1.136.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
netty-handler@4.1.111.Final
4.1.137.Final
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
netty-handler@4.1.82.Final
4.1.137.Final
1
quay.io/keycloak/keycloak-operator:26.7.268b1e5805b99
netty-handler@4.1.136.Final
4.1.137.Final
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
netty-handler@4.1.82.Final
4.1.137.Final
1
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
netty-handler@4.1.132.Final
4.1.137.Final
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
netty-handler@4.1.127.Final
4.1.137.Final
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
netty-handler@4.1.133.Final
4.1.137.Final
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
netty-handler@4.1.130.Final
4.1.137.Final
1
quay.io/microcks/microcks-operator:0.0.1196d1054d4a61
netty-handler@4.1.128.Final
4.1.137.Final
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
netty-handler@4.1.94.Final
4.1.137.Final
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
netty-handler@4.1.105.Final
4.1.137.Final
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
netty-handler@4.1.105.Final
4.1.137.Final
1
quay.io/poundex/tekton-ci-environment-injector:0.2.46dd65f22949c
netty-handler@4.2.15.Final
4.2.17.Final
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
netty-handler@4.2.15.Final
4.2.17.Final
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
netty-handler@4.1.115.Final
4.1.137.Final
1
quay.io/strimzi/operator:0.45.158c727cd2e68
netty-handler@4.1.118.Final
4.1.137.Final
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
netty-handler@4.1.94.Final
4.1.137.Final
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
netty-handler@4.1.115.Final
4.1.137.Final
1
registry.gitlab.com/lenitech/docker/keycloak:26.7.3-0297e9df1489d
netty-handler@4.1.136.Final
4.1.137.Final
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.