StackRadar

CVE-2026-75806

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,956
of 17,985 indexed, latest versions
Container images
2,991
deployed by those charts
Fix available
2 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 2,956 of 17,985 indexed charts deploy, on 2,991 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more3.0.2-0ubuntu1.30, 3.0.13-0ubuntu3.16, 3.5.5-1ubuntu3.6, 3.5.7-1~deb13u32,694
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2297
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 moreno fix listed22
OSV records
ALPINE-CVE-2026-75806DEBIAN-CVE-2026-75806ECHO-c4dc-a1f8-f0aeUBUNTU-CVE-2026-75806
Also known as
USN-8847-1
Trending
Rank 4 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,956 by stars
ChartLatestAffected imagesRadar Score
endlessh-gozekker6Verified publisher0.4.01 of 1See more

endlessh-go zekker6 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
ghcr.io/shizunge/endlessh-go:2026.0730.08826dad32623
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

684
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,018
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,135
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
no fix listed

Open the chart page →

9,696
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
openssl@3.0.2-0ubuntu1.30
no fix listed

Open the chart page →

6,744

Container images carrying it

2,991 by charts deploying them

A fixed version is listed for 2 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/jossware/node-provider-labeler:v0.8.0f80e85291439
openssl@3.0.13-1~deb12u1
no fix listed
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
openssl@1.1.1f-1ubuntu2.10
no fix listed
1
ghcr.io/juanfont/headscale:0.29.3:v0.29.30e7f1c6e4ce6
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/juanfont/headscale:0.29.4-debug2380cdb4951e
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/juanfont/headscale:0.29.18453e47ea6bf
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/juanfont/headscale:0.29.48833f828b414
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/juicerescue/juicepassproxy:0.5.1984dc4f19162
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/justarchinet/archisteamfarm:6.3.10.107286b8b41a1
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
openssl@3.3.3-r0
3.3.7-r2
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
openssl@1.1.1f-1ubuntu2.16
no fix listed
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
openssl@1.1.1f-1ubuntu2.10
no fix listed
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
openssl@1.1.1f-1ubuntu2.3
no fix listed
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
openssl@1.1.1f-1ubuntu2.4
no fix listed
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
openssl@1.1.1f-1ubuntu2.13
no fix listed
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
openssl@1.1.1f-1ubuntu2.5
no fix listed
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
openssl@1.1.1f-1ubuntu2.4
no fix listed
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.30
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
openssl@1.1.1f-1ubuntu2.3
no fix listed
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
openssl@1.1.1f-1ubuntu2.16
no fix listed
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
openssl@1.1.1f-1ubuntu2.12
no fix listed
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
openssl@1.1.1f-1ubuntu2.12
no fix listed
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.30
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
openssl@1.1.1f-1ubuntu2.3
no fix listed
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
openssl@1.1.1f-1ubuntu2.4
no fix listed
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.30
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
openssl@1.1.1f-1ubuntu2.8
no fix listed
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
openssl@1.1.1f-1ubuntu2.16
no fix listed
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
openssl@1.1.1f-1ubuntu2.3
no fix listed
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
openssl@1.1.1f-1ubuntu2.12
no fix listed
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
openssl@1.1.1f-1ubuntu2.19
no fix listed
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4-thick3c20900b5381
openssl@3.5.4-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
openssl@3.0.16-1~deb12u1
no fix listed
1
ghcr.io/k8snetworkplumbingwg/multus-cni:latest-thickbc058c992eec
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/k8snetworkplumbingwg/multus-cni:stableec4e5dfe12b6
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/kamu-data/kamu-api-server:0.91.04572427a9db1
openssl@1.1.1f-1ubuntu2.24
no fix listed
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/keiailab/nodevitals:0.8.597107e46f0d3
openssl@3.0.20-1~deb12u2
no fix listed
1
ghcr.io/kikplate/kikplate-api:main2fbce0601a3c
openssl@3.3.7-r0
3.3.7-r2
1
ghcr.io/klicktipp/csa-exporter:0.3.12c69513f9d85
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/klicktipp/snds-exporter:v0.2.4a23b389cb3c5
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
openssl@3.3.7-r0
3.3.7-r2
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
openssl@1.1.1-1ubuntu2.1~18.04.20
no fix listed
1
ghcr.io/krateoplatformops/app:1.2.86aaa3fe7d5c74
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/krateoplatformops/deployment-service:1.2.59da9f93f2f731
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/krateoplatformops/finops-database-handler:0.5.32550427988e3
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/krateoplatformops/finops-webservice-api-mock:0.1.00877e9452d14
openssl@3.0.11-1~deb12u2
no fix listed
1
ghcr.io/krateoplatformops/krateo-frontend:2.4.26aff913c8bfe
openssl@3.0.15-1~deb12u1
no fix listed
1
ghcr.io/krateoplatformops/kubectl:1.33.1393d2a3f53a5
openssl@3.0.16-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.