StackRadar

CVE-2026-75806

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,955
of 17,988 indexed, latest versions
Container images
2,998
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-75806 affecting package openssl 3.3.7-6

Carried by container images the latest versions of 2,955 of 17,988 indexed charts deploy, on 2,998 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+123 more3.0.2-0ubuntu1.30, 3.0.13-0ubuntu3.16, 3.5.5-1ubuntu3.6, 3.5.7-1~deb13u32,690
opensslapk3.3.1-r3, 3.3.2-r4, 3.3.2-r5, 3.3.3-r0+5 more3.3.7-r2297
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+14 moreno fix listed23
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+5 moreno fix listed22
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl3, 3.3.7-4.azl3no fix listed11
OSV records
ALPINE-CVE-2026-75806AZL-105597DEBIAN-CVE-2026-75806ECHO-c4dc-a1f8-f0aeUBUNTU-CVE-2026-75806
Also known as
USN-8847-1
Trending
Rank 4 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

2,955 by stars
ChartLatestAffected imagesRadar Score
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3

Open the chart page →

1,859
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
openssl@3.0.20-1~deb12u2
no fix listed

Open the chart page →

5,004
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
openssl@3.0.17-1~deb12u2
no fix listed

Open the chart page →

2,120
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
openssl@1.1.1-1ubuntu2.1~18.04.14
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
openssl@1.1.1f-1ubuntu2.10
no fix listed

Open the chart page →

9,697
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-75806.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
openssl@3.0.2-0ubuntu1.30
no fix listed

Open the chart page →

6,754

Container images carrying it

2,998 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
3.5.7-1~deb13u3
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
openssl@3.5.5-1ubuntu3.3
3.5.5-1ubuntu3.6
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r2
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.7-r2
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssl@3.0.9-1
no fix listed
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
openssl@3.0.13-0ubuntu3.15
3.0.13-0ubuntu3.16
1
registry.gitlab.com/dyff/dyff-api:0.57.912b6fc5c8fc5
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r2
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.1126450354eba9
openssl@3.5.5-1ubuntu3.5
3.5.5-1ubuntu3.6
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
openssl@3.0.20-1~deb12u1
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.4001e589acf2e
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestc5faeae6b5d0
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
openssl@3.5.6-1~deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.7-1~deb13u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
openssl@3.0.20-1~deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
openssl@3.5.6-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.104019bb2e325
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.198d46dc7e071
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.19df7d5aa03fe
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabb21661438ee9
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.25b0d50fcd5ea
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.14ed6de4d77e1
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.6.2-gitlab1a80159109e74
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
openssl@3.5.7-1~deb13u2
3.5.7-1~deb13u3
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
no fix listed
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod764ca253f951
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbdb1bcedf26f
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-workspaces:prode64a1cb3aa42
openssl@3.3.7-r0
3.3.7-r2
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
openssl@3.0.20-1~deb12u1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
no fix listed
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.7-1~deb13u3
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
no fix listed
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r2
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
openssl@3.0.20-1~deb12u2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 4 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.