StackRadar

CVE-2026-9076

High

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,488
of 17,813 indexed, latest versions
Container images
2,747
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-9076 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 2,488 of 17,813 indexed charts deploy, on 2,747 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+103 more1.0.1f-1ubuntu2.27+esm14, 1.0.2g-1ubuntu4.20+esm16, 1.1.1-1ubuntu2.1~18.04.23+esm9, 1.1.1f-1ubuntu2.24+esm4+6 more1,821
opensslapk3.2.0-r0, 3.3.1-r3, 3.3.1-r4, 3.3.2-r0+21 more3.3.7-r1, 3.5.7-r0, 3.6.3-r0921
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm520
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-9076CGA-6mcp-mm5g-jxrjCGA-847w-c3x7-8qp6DEBIAN-CVE-2026-9076UBUNTU-CVE-2026-9076AZL-89934
Also known as
CGA-6p96-39qh-rm77, CGA-f2mp-q84v-4jv2, USN-8414-1, USN-8414-2

Charts affected

2,488 by stars
ChartLatestAffected imagesRadar Score
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

7,012
difydify-helmVerified publisher0.38.02 of 11See more

dify dify-helm 0.38.0

2 of the 11 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.15750e1111426e
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
langgenius/dify-web:1.16.187dd47e4e28f
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

64,141
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11

Open the chart page →

3,275
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

1,990
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

1,752
hydraory0.64.01 of 2See more

hydra ory 0.64.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
oryd/hydra:v26.2.0ff67c7fb5f95
openssl@3.3.6-r0
3.3.7-r1

Open the chart page →

1,318
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm16
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm16

Open the chart page →

137,802
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

1,871
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
openssl@3.3.4-r0
3.3.7-r1

Open the chart page →

16,469
openbaoopenbaoVerified publisher0.29.51 of 2See more

openbao openbao 0.29.5

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:1.7.2ae3d307658b7
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

1,521
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.02 of 5See more

openproject openproject-helm-charts 13.12.0

2 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
openproject/hocuspocus:release-338001b288dc1359dfb5
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

20,467
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2

Open the chart page →

11,588
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.25
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.25
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.25
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
openssl@3.0.2-0ubuntu1.6
3.0.2-0ubuntu1.25

Open the chart page →

33,692
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
openssl@3.3.7-r0
3.3.7-r1

Open the chart page →

9,371
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
openssl@3.0.9-1
3.0.20-1~deb12u2

Open the chart page →

4,347
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

6,620
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2

Open the chart page →

7,911
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

2,406
cloudflaredkubitodevVerified publisher1.7.91 of 1See more

cloudflared kubitodev 1.7.9

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2026.3.06b599ca3e974
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

1,481
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

6,159
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
openssl@3.0.2-0ubuntu1.12
3.0.2-0ubuntu1.25

Open the chart page →

12,947
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

3,065
netbirdjaconiVerified publisher0.15.13 of 4See more

netbird jaconi 0.15.1

3 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
netbirdio/relay:0.45.1872e3add0e1e
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
netbirdio/signal:0.45.146ce5a45538f
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

8,134
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

5,104
argocdnicklasfrahm-argocdVerified publisher0.3.02 of 2See more

argocd nicklasfrahm-argocd 0.3.0

2 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
openssl@3.3.3-r0
3.3.7-r1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

5,494
oneuptimeoneuptimeOfficialVerified publisher13.0.81 of 7See more

oneuptime oneuptime 13.0.8

1 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.74f94badaca11
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

11,196
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

5,752
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
openssl@3.0.13-0ubuntu3.2
3.0.13-0ubuntu3.11

Open the chart page →

3,453
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
openssl@1.1.1-1ubuntu2.1~18.04.6
1.1.1-1ubuntu2.1~18.04.23+esm9

Open the chart page →

81,512
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
openssl@1.1.1f-1ubuntu2.13
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

7,942
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,178
falcosidekickfalcosecurity0.14.01 of 1See more

falcosidekick falcosecurity 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
falcosecurity/falcosidekick:2.32.01976da721518
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

1,775
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

12,208
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

5,428
plane-cemakeplaneOfficialVerified publisher1.8.11 of 11See more

plane-ce makeplane 1.8.1

1 of the 11 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
valkey/valkey:7.2.11-alpine10328d00120d
openssl@3.5.5-r0
3.5.7-r0

Open the chart page →

5,004
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25
milvusdb/etcd:3.5.25-r1fededb2f2d63
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.25

Open the chart page →

11,175
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

5,630
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

6,435
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

87,171
ansible-semaphorecloudhippieVerified publisher15.2.111 of 1See more

ansible-semaphore cloudhippie 15.2.11

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
openssl@3.3.7-r0
3.3.7-r1

Open the chart page →

1,430
rustfscloudpirates-rustfsVerified publisher0.11.51 of 1See more

rustfs cloudpirates-rustfs 0.11.5

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
rustfs/rustfs:1.0.0-beta.13c2d55977829
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

880
zookeepercloudpirates-zookeeperVerified publisher0.15.01 of 1See more

zookeeper cloudpirates-zookeeper 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/zookeeper:3.9.57d0f24ebb67b
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

2,989
codefreshcodefresh-onpremOfficialVerified publisher2.12.154 of 42See more

codefresh codefresh-onprem 2.12.15

4 of the 42 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
bitnamilegacy/rabbitmq:4.1.39e635efba431
openssl@3.0.17-1~deb12u1
3.0.20-1~deb12u2
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
openssl@3.0.17-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

15,557
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

1,544
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

3,024
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2api:3.86f56d239d280
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2auth:3.833ecfda16608
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2notifier:3.8f190a6212195
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2rulesengine:3.8259503496ff9
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2scheduler:3.8b1de2055c362
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2sensorcontainer:3.8b1a338f64773
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2stream:3.81c8904a3bf67
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2timersengine:3.81bf35bfaf00c
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2web:3.809989a26c8b7
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
stackstorm/st2workflowengine:3.819fdfffdbba8
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

740,587
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.11
library/kong:3.8.0fd78090e9e77
openssl@3.0.2-0ubuntu1.29
no fix listed
supabase/edge-runtime:v1.59.0eff9c554d649
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
supabase/postgres-meta:v0.84.2d0a96973e9f1
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
supabase/realtime:v2.33.8d207e6e23ad3
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2
supabase/studio:20241021-9f9b08326d8070c55e9
openssl@3.0.14-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

23,182
renterdartur9010Verified publisher1.4.41 of 2See more

renterd artur9010 1.4.4

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

8,651
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
openssl@3.0.18-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

9,698
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
openssl@3.3.5-r0
3.3.7-r1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
openssl@3.3.5-r0
3.3.7-r1
yuzutech/kroki-excalidraw:0.29.157917319ea70
openssl@3.3.5-r0
3.3.7-r1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
openssl@3.3.5-r0
3.3.7-r1

Open the chart page →

7,371

Container images carrying it

2,747 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
openssl@3.5.4-r0
3.5.7-r0
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-frontend:0.6.47e27863545fc
openssl@3.3.3-r0
3.3.7-r1
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
1
ghcr.io/reiche-world/traefik-secrets-exporter:0.0.21485ff93cbf9
openssl@3.5.4-r0
3.5.7-r0
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2
1
ghcr.io/robbeverhelst/preparr:latest9acc172942f3
openssl@3.5.6-r0
3.5.7-r0
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
openssl@3.0.9-1
3.0.20-1~deb12u2
1
ghcr.io/sagernet/sing-box:v1.12.03c1ee82d450d
openssl@3.5.1-r0
3.5.7-r0
1
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm9
1
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
openssl@1.1.1-1ubuntu2.1~18.04.19
1.1.1-1ubuntu2.1~18.04.23+esm9
1
ghcr.io/schaka/janitorr:native-stable7cfe1e0c41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
openssl@3.5.5-r0
3.5.7-r0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
ghcr.io/sebadob/rauthy:0.35.2a73dbf58359f
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
openssl@3.5.5-r0
3.5.7-r0
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
openssl@3.5.0-r0
3.5.7-r0
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
openssl@3.5.6-r0
3.5.7-r0
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2
1
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.11
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
openssl@3.5.4-r0
3.5.7-r0
1
ghcr.io/sooperset/mcp-atlassian:0.11.927c8e5b890e1
openssl@3.5.0-r0
3.5.7-r0
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
openssl@1.1.1f-1ubuntu2.24
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/spidernet-io/spiderpool/spiderpool-plugins:19f19457ae7cec86457b0411543a3cf21dd9f95a8edc39be1e22
openssl@3.5.6-r0
3.5.7-r0
1
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
openssl@1.1.1f-1ubuntu2.23
1.1.1f-1ubuntu2.24+esm4
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.11
1
ghcr.io/substra/substra-backend:1.0.121967f54ec86
openssl@3.0.13-0ubuntu3.4
3.0.13-0ubuntu3.11
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.