StackRadar

CVE-2026-9076

High

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,223
of 17,787 indexed, latest versions
Container images
2,437
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-9076 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 2,223 of 17,787 indexed charts deploy, on 2,437 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+103 more1.0.1f-1ubuntu2.27+esm14, 1.0.2g-1ubuntu4.20+esm16, 1.1.1-1ubuntu2.1~18.04.23+esm9, 1.1.1f-1ubuntu2.24+esm4+6 more1,792
opensslapk3.2.0-r0, 3.3.1-r4, 3.3.2-r0, 3.3.2-r2+13 more3.5.7-r0, 3.6.3-r0640
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+8 moreno fix listed16
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.10+2 more1.0.2n-1ubuntu5.13+esm515
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-9076CGA-6mcp-mm5g-jxrjCGA-847w-c3x7-8qp6DEBIAN-CVE-2026-9076UBUNTU-CVE-2026-9076AZL-89934
Also known as
CGA-6p96-39qh-rm77, CGA-f2mp-q84v-4jv2, USN-8414-1, USN-8414-2

Charts affected

2,223 by stars
ChartLatestAffected imagesRadar Score
syncthingbrandan-schmitz-helm-chartsVerified publisher2.1.01 of 1See more

syncthing brandan-schmitz-helm-charts 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
syncthing/syncthing:2.1.1775c4aac4862
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,230
brightdata-exporterbrightdata-chartsVerified publisher0.2.171 of 1See more

brightdata-exporter brightdata-charts 0.2.17

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,282
buildkite-agent-metricsbuildkite-agent-metrics0.1.01 of 1See more

buildkite-agent-metrics buildkite-agent-metrics 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
public.ecr.aws/buildkite/agent-metrics:v5.11.016e7f5c7161e
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

1,534
static-httpserverbyjgVerified publisher0.2.01 of 1See more

static-httpserver byjg 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
byjg/static-httpserver:latest562cc8b9c40b
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

677
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

84,678
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

84,678
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11

Open the chart page →

3,713
cert-vaultcert-vaultOfficialVerified publisher2.12.05 of 7See more

cert-vault cert-vault 2.12.0

5 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

15,995
passbolt-hachristianhuthVerified publisher6.0.12 of 4See more

passbolt-ha christianhuth 6.0.1

2 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

10,873
squestchristianhuthVerified publisher6.6.73 of 4See more

squest christianhuth 6.6.7

3 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

10,008
typo3christianhuthVerified publisher7.7.02 of 2See more

typo3 christianhuth 7.7.0

2 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2
martinhelmich/typo3:12.4c83a4f3fd7ae
openssl@3.0.18-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

8,524
chromadbchromadb-helmVerified publisher0.2.21 of 1See more

chromadb chromadb-helm 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.3cfd193653bd6
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,444
nethermindchronicleVerified publisher0.0.131 of 1See more

nethermind chronicle 0.0.13

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
nethermind/nethermind:1.31.9aeca3b55bda5
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

2,070
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2

Open the chart page →

1,521
cloudflared-ingress-operatorcloudflared-ingress-operatorVerified publisher0.3.21 of 1See more

cloudflared-ingress-operator cloudflared-ingress-operator 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

1,736
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
openssl@1.0.2g-1ubuntu4.10
1.0.2g-1ubuntu4.20+esm16

Open the chart page →

36,132
openstack-manila-csicloud-provider-openstack2.36.31 of 5See more

openstack-manila-csi cloud-provider-openstack 2.36.3

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

3,749
cloudttycloudtty0.8.92 of 2See more

cloudtty cloudtty 0.8.9

2 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
openssl@3.5.4-r0
3.5.7-r0
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
openssl@3.0.18-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

3,958
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
openssl@3.0.2-0ubuntu1.16
3.0.2-0ubuntu1.25

Open the chart page →

4,896
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

10,076
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
openssl@3.0.9-1
3.0.20-1~deb12u2

Open the chart page →

9,736
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

11,236
oci-registrycronce0.4.51 of 1See more

oci-registry cronce 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
mcronce/oci-registry:v0.4.509519cd7bd2f
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

1,306
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

12,924
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
openssl@3.0.2-0ubuntu1.15
3.0.2-0ubuntu1.25

Open the chart page →

5,438
aibrixdanchevVerified publisher0.7.01 of 5See more

aibrix danchev 0.7.0

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
aibrix/metadata-service:v0.7.063fb81a64377
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

5,298
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm4
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

38,424
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

4,909
dbrepodbrepo1.13.315 of 25See more

dbrepo dbrepo 1.13.3

15 of the 25 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/postgresql:17.0.0-debian-12-r9d885ac277163
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/valkey:latest0384ca2eec63
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

50,281
dcachedcache0.1.01 of 4See more

dcache dcache 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
kroniak/ssh-client:latest3aef87e1a00b
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

487
mealiedeimosfr-charts1.0.151 of 1See more

mealie deimosfr-charts 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

4,042
kubedashdevopstalesOfficialVerified publisher4.0.03 of 8See more

kubedash devopstales 4.0.0

3 of the 8 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/postgres:18.3a9abf4275f9e
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2
library/redis:8.6.2009cc37796fb
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2
oliver006/redis_exporter:v1.82.0-alpineda9e89ee4e75
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

9,239
dial-coredialOfficialVerified publisher6.0.01 of 2See more

dial-core dial 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,533
powershelluniversaldigitalhubVerified publisher0.1.21 of 1See more

powershelluniversal digitalhub 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

6,978
directusdirectus-io2.1.03 of 3See more

directus directus-io 2.1.0

3 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2
directus/directus:12.0.29c8470ea465c
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

7,518
smtp-relaydjjudas21Verified publisher0.8.01 of 1See more

smtp-relay djjudas21 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
djjudas21/smtp-relay:0.11.0ffd8143952f6
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

675
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,884
dominodominoVerified publisher0.1.112 of 3See more

domino domino 0.1.11

2 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
openssl@3.5.1-1+deb13u1
3.5.6-1~deb13u2
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

8,842
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
openssl@3.0.2-0ubuntu1.17
3.0.2-0ubuntu1.25

Open the chart page →

10,884
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

18,402
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

5,724
glpieftechcombr-glpiVerified publisher2.12.01 of 5See more

glpi eftechcombr-glpi 2.12.0

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

4,398
elchi-stackelchi1.13.04 of 10See more

elchi-stack elchi 1.13.0

4 of the 10 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.81ffa82edee00
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm4
envoyproxy/envoy:v1.33.056da5afd7df3
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
grafana/grafana:12.2.074144189b384
openssl@3.5.1-r0
3.5.7-r0
library/mongo:6.0.12646902910d6a
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25

Open the chart page →

15,501
enavenav-service-architectureVerified publisher0.0.78 of 10See more

enav enav-service-architecture 0.0.7

8 of the 10 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-eureka:latest05002092c621
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
openssl@3.5.6-r0
3.5.7-r0
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

15,865
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

31,572
kubevirtencircle360-ossVerified publisher0.2.11 of 1See more

kubevirt encircle360-oss 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
quay.io/kubevirt/virt-operator:v1.7.037d2ef21e3e5
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

856
eoapieoapiOfficialVerified publisher0.16.21 of 7See more

eoapi eoapi 0.16.2

1 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
alpine/kubectl:1.34.18413f8890d19
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

6,303
copypartyernail-copyparty2.0.01 of 1See more

copyparty ernail-copyparty 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
copyparty/ac:1.19.200a0a8605062c
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,690
scoolderudikaVerified publisher0.3.01 of 1See more

scoold erudika 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
erudikaltd/scoold:1.66.0949c56b57e8f
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,606
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25

Open the chart page →

3,087

Container images carrying it

2,437 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
library/ghost:6.22.0-alpine3.23ac533a6988ee
openssl@3.5.5-r0
3.5.7-r0
1
library/haproxy:3.1-alpine475863a372c9
openssl@3.5.6-r0
3.5.7-r0
1
library/haproxy:3.1-bookworm49a0a0d6f0b8
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2
1
library/haproxy:2.9.6fc5748ff7c72
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
1
library/httpd:2.4.631ae8051591a5
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
1
library/influxdb:1.12.3-meta8812029260b5
openssl@3.0.18-1~deb12u2
3.0.20-1~deb12u2
1
library/influxdb:1.12.3-datab0f9fc41ed79
openssl@3.0.18-1~deb12u2
3.0.20-1~deb12u2
1
library/kibana:7.17.150172f1c538e7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
1
library/kibana:8.18.004c0fc150f3a
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm4
1
library/kibana:7.17.8c5781ba340ef
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
library/kibana:7.17.3e2e2031c15be
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm4
1
library/kong:3.8.0712e407b20ea
openssl@3.0.2-0ubuntu1.26
no fix listed
1
library/logstash:7.17.817a4f64e9cf5
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:10.7.307e06f2e7ae9
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:10.11.21c33370a599c
openssl@3.0.2-0ubuntu1.9
3.0.2-0ubuntu1.25
1
library/mariadb:10.422edfe1c7834
openssl@1.1.1f-1ubuntu2.22
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:10.8.2-focal490f01279be1
openssl@1.1.1f-1ubuntu2.10
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:12.0.25b6a1eac15b8
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
library/mariadb:10.6.218a16204dc96c
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:10.79a48ac9f196f
openssl@1.1.1f-1ubuntu2.17
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:12.2.2b1cb255a9939
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
library/mariadb:10.10.2bfc25a68e113
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25
1
library/mariadb:10.6.15e22328f4d714
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm4
1
library/mariadb:10.9.4fbb8456ebdb1
openssl@3.0.2-0ubuntu1.7
3.0.2-0ubuntu1.25
1
library/mariadb:11.7.2fcc7fcd7114a
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
library/matomo:5.1.2-apache2415789e1602
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
library/memcached:1.6.4226983a43c918
openssl@3.5.6-1~deb13u1
3.5.6-1~deb13u2
1
library/memcached:1.6.41-alpine65c80b311a96
openssl@3.5.6-r0
3.5.7-r0
1
library/memcached:1.6.39-alpine3.227b45203a99eb
openssl@3.5.4-r0
3.5.7-r0
1
library/memcached:1.6.409ae868852d0b
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2
1
library/memcached:1.6.40cc523a19da58
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2
1
library/memcached:1.6.38-alpinee93269864a7d
openssl@3.5.1-r0
3.5.7-r0
1
library/mongo:7.0.140032d2ca20db
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
1
library/mongo:4.4.1305678ae4e5e1
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm4
1
library/mongo:3.6146c1fd999a6
openssl@1.0.2g-1ubuntu4.19
1.0.2g-1ubuntu4.20+esm16
1
library/mongo:5.0.32-focal3b6c281e1c08
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm4
1
library/mongo:4.4-bionic3d0e6df9fd5b
openssl@1.1.1-1ubuntu2.1~18.04.9
1.1.1-1ubuntu2.1~18.04.23+esm9
1
library/mongo:5.0.14-focal50cae5081ab4
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
library/mongo:6.0.12646902910d6a
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25
1
library/mongo:4.2699d652ed674
openssl@1.1.1-1ubuntu2.1~18.04.23
1.1.1-1ubuntu2.1~18.04.23+esm9
1
library/mongo:4.2.16ca49afbcb2b
openssl@1.1.1-1ubuntu2.1~18.04.4
1.1.1-1ubuntu2.1~18.04.23+esm9
1
library/mongo:6.0.271a63fc2438e
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
library/mongo:5.0.217c81758cb295
openssl@1.1.1f-1ubuntu2.19
1.1.1f-1ubuntu2.24+esm4
1
library/mongo:7.0.28-jammy88785f6f665a
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.25
1
library/mongo:4.2.21-bionic9cb28f7291d9
openssl@1.1.1-1ubuntu2.1~18.04.20
1.1.1-1ubuntu2.1~18.04.23+esm9
1
library/mongo:7.0.12ae1cf99fa7bf
openssl@3.0.2-0ubuntu1.17
3.0.2-0ubuntu1.25
1
library/mongo:4.4.18d23ec07162ca
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
library/mongo:8.0.11dca8d11fe467
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
library/mysql:8.0-debian9382e4f6f7f0
openssl@3.0.19-1~deb12u2
3.0.20-1~deb12u2
1
library/nats:2.12.2-alpine2d5fce3229ae
openssl@3.5.4-r0
3.5.7-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.