StackRadar

CVE-2026-9076

High

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,488
of 17,813 indexed, latest versions
Container images
2,747
deployed by those charts
Fix available
4 of 5
affected packages

CVE-2026-9076 affecting package openssl for versions less than 3.3.7-3

Carried by container images the latest versions of 2,488 of 17,813 indexed charts deploy, on 2,747 images.

Affected packageAffected versionsFixed inImages
openssldeb1.0.1f-1ubuntu2.5, 1.0.1f-1ubuntu2.8, 1.0.1f-1ubuntu2.25, 1.0.1f-1ubuntu2.27+103 more1.0.1f-1ubuntu2.27+esm14, 1.0.2g-1ubuntu4.20+esm16, 1.1.1-1ubuntu2.1~18.04.23+esm9, 1.1.1f-1ubuntu2.24+esm4+6 more1,821
opensslapk3.2.0-r0, 3.3.1-r3, 3.3.1-r4, 3.3.2-r0+21 more3.3.7-r1, 3.5.7-r0, 3.6.3-r0921
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+13 moreno fix listed22
openssl1.0deb1.0.2n-1ubuntu5.3, 1.0.2n-1ubuntu5.4, 1.0.2n-1ubuntu5.6, 1.0.2n-1ubuntu5.7+4 more1.0.2n-1ubuntu5.13+esm520
opensslrpm3.3.5-1.azl3, 3.3.5-3.azl3, 3.3.5-5.azl33.3.7-35
OSV records
ALPINE-CVE-2026-9076CGA-6mcp-mm5g-jxrjCGA-847w-c3x7-8qp6DEBIAN-CVE-2026-9076UBUNTU-CVE-2026-9076AZL-89934
Also known as
CGA-6p96-39qh-rm77, CGA-f2mp-q84v-4jv2, USN-8414-1, USN-8414-2

Charts affected

2,488 by stars
ChartLatestAffected imagesRadar Score
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

9,969
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
openssl@1.1.1f-1ubuntu2.8
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

10,174
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
openssl@3.0.19-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

5,704
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

6,148
fluent-bitromanow-helm-chartsVerified publisher1.7.31 of 1See more

fluent-bit romanow-helm-charts 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
fluent/fluent-bit:4.0-debuge76397ef3983
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2

Open the chart page →

8,008
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

6,957
kube-state-metricsromanow-helm-chartsVerified publisher1.7.21 of 1See more

kube-state-metrics romanow-helm-charts 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
bitnamilegacy/kube-state-metrics:204a3044b384b
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

2,725
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

7,607
routehub-client-hubroutehub-helm1.0.02 of 3See more

routehub-client-hub routehub-helm 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
openssl@1.1.1f-1ubuntu2.20
1.1.1f-1ubuntu2.24+esm4
timescale/timescaledb-ha:pg164f288c0a5213
openssl@3.0.2-0ubuntu1.29
no fix listed

Open the chart page →

12,916
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

2,988
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
openssl@3.5.1-1
3.5.6-1~deb13u2

Open the chart page →

4,020
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

5,392
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
openssl@1.1.1-1ubuntu2.1~18.04.14
1.1.1-1ubuntu2.1~18.04.23+esm9

Open the chart page →

13,602
kyoorubxkubeVerified publisher0.1.105 of 9See more

kyoo rubxkube 0.1.10

5 of the 9 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
openssl@3.3.2-r4
3.3.7-r1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

30,977
conference-appsalaboy1.0.03 of 7See more

conference-app salaboy 1.0.0

3 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
openssl@3.0.2-0ubuntu1.10
3.0.2-0ubuntu1.25

Open the chart page →

11,094
devpisb-helm-charts0.3.01 of 1See more

devpi sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
jonasal/devpi-server:6.17.0-alpineec1eee99a18d
openssl@3.5.4-r0
3.5.7-r0

Open the chart page →

959
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2

Open the chart page →

38,817
schemaheroschemahero1.4.01 of 1See more

schemahero schemahero 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
schemahero/schemahero-manager:0.22.11609e1a05cd3
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11

Open the chart page →

2,208
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

5,240
sentry-k8ssentry-k8sVerified publisher1.4.14 of 11See more

sentry-k8s sentry-k8s 1.4.1

4 of the 11 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
openssl@3.0.2-0ubuntu1.19
3.0.2-0ubuntu1.25
library/nginx:1.31.0-alpine2f07d83bf561
openssl@3.5.6-r0
3.5.7-r0
library/redis:6.2.20-alpine77697a75da9f
openssl@3.3.5-r0
3.3.7-r1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

17,047
seq-input-gelfseq-input-gelfVerified publisher0.3.11 of 2See more

seq-input-gelf seq-input-gelf 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
datalust/seq-input-gelf:3.0.441-x643de34aed5642
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

3,427
vuiseriohub1.0.62 of 3See more

vui seriohub 1.0.6

2 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
dserio83/velero-watchdog:0.1.8d5deae589229
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

11,654
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

1,824
scaffoldsigstoreVerified publisher0.6.1152 of 15See more

scaffold sigstore 0.6.115

2 of the 15 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
curlimages/curldigest-pinned:8.17.0935d9100e9ba
openssl@3.5.4-r0
3.5.7-r0
library/redisdigest-pinned148bb5411c18
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

7,854
mssqlserver-2019simcube1.2.31 of 1See more

mssqlserver-2019 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
openssl@1.1.1f-1ubuntu2.12
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

6,926
clickhousesinextraVerified publisher0.22.01 of 1See more

clickhouse sinextra 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3.1092098d3b31dd
openssl@3.0.2-0ubuntu1.23
3.0.2-0ubuntu1.25

Open the chart page →

2,036
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

4,645
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

2,995
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

251,237
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2
valkey/valkey:8.1.61f84517eca8e
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2

Open the chart page →

3,107
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
openssl@3.5.1-1
3.5.6-1~deb13u2

Open the chart page →

14,621
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
openssl@3.5.4-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

7,432
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.41 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
openssl@3.0.19-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

4,701
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

5,758
speckle-serverspeckleVerified publisher2.26.34 of 4See more

speckle-server speckle 2.26.3

4 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
speckle/speckle-monitor-deployment:2.26.3d51e1b0cf231
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
speckle/speckle-preview-service:2.26.3092384dba45d
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2
speckle/speckle-server:2.26.379f14a2bf931
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
speckle/speckle-webhook-service:2.26.3c58eb372c488
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

10,579
ocean-metric-exporterspot1.1.11 of 1See more

ocean-metric-exporter spot 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
gcr.io/spotinst-artifacts/spot-ocean-metric-exporter:1.0.5ae57b62291aa
openssl@3.5.1-r0
3.5.7-r0

Open the chart page →

1,487
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
openssl@3.0.2-0ubuntu1.20
3.0.2-0ubuntu1.25

Open the chart page →

2,666
gethstakewise2.5.81 of 3See more

geth stakewise 2.5.8

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ethereum/client-go:v1.15.101f36ca5922a5
openssl@3.3.3-r0
3.3.7-r1

Open the chart page →

1,289
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2

Open the chart page →

4,741
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
openssl@1.1.1f-1ubuntu2.16
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

13,622
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
openssl@1.1.1f-1ubuntu2.4
1.1.1f-1ubuntu2.24+esm4

Open the chart page →

102,717
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11
alazidis/stornx:1.1.1602d4f7f090c
openssl@3.0.18-1~deb12u2
3.0.20-1~deb12u2
istio/pilot:1.29.1f8b0e412ac4a
openssl@3.0.13-0ubuntu3.7
3.0.13-0ubuntu3.11

Open the chart page →

11,854
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
openssl@3.0.13-0ubuntu3.9
3.0.13-0ubuntu3.11

Open the chart page →

2,941
supabasesupabse0.8.08 of 11See more

supabase supabse 0.8.0

8 of the 11 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
kong/kong:3.9.16addf50e6bd8
openssl@3.0.13-0ubuntu3.5
3.0.13-0ubuntu3.11
supabase/edge-runtime:v1.74.02781daf92394
openssl@3.0.19-1~deb12u2
3.0.20-1~deb12u2
supabase/gotrue:v2.189.0385184459f57
openssl@3.5.6-r0
3.5.7-r0
supabase/postgres:17.6.1.136f371b5f3f2ac
openssl@3.5.6-r0
3.5.7-r0
supabase/postgres-meta:v0.96.6a84cc713585e
openssl@3.0.19-1~deb12u2
3.0.20-1~deb12u2
supabase/realtime:v2.102.3aa1c92c0cf32
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2
supabase/storage-api:v1.60.4c8eb9858eafe
openssl@3.5.6-r0
3.5.7-r0

Open the chart page →

18,318
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
openssl@3.0.2-0ubuntu1.18
3.0.2-0ubuntu1.25

Open the chart page →

2,162
syncerdsyncerdVerified publisher0.2.21 of 1See more

syncerd syncerd 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/clouddrove/syncerd:latest73a1bb038de3
openssl@3.3.7-r0
3.3.7-r1

Open the chart page →

193
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2

Open the chart page →

3,374
headscaleszpadel-chartsVerified publisher0.30.21 of 3See more

headscale szpadel-charts 0.30.2

1 of the 3 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.6.39476cc5adb12
openssl@3.0.18-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

1,912
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

9,166
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-9076.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2

Open the chart page →

9,166

Container images carrying it

2,747 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/mittwald/kube-httpcache:stable2169032c5840
openssl@3.0.16-1~deb12u1
3.0.20-1~deb12u2
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
openssl@1.0.2g-1ubuntu4.17
1.0.2g-1ubuntu4.20+esm16
1
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
openssl@3.3.7-r0
3.3.7-r1
1
quay.io/opsmxpublic/opa:opa-sidecar-v1.03dcbf3caa454
openssl@3.5.4-r0
3.5.7-r0
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
openssl@3.0.13-0ubuntu3.6
3.0.13-0ubuntu3.11
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
openssl@1.0.2g-1ubuntu4.15
1.0.2g-1ubuntu4.20+esm16
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
openssl@3.5.4-1~deb13u1
3.5.6-1~deb13u2
1
quay.io/opstree/fluent-bit:5.0.3391eef5a68ff
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/k8s-sidecar:2.7.126aa9bb3386b
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/k8s-sidecar:2.7.37075d455b219
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/opstree/memcached:1.6.38-alpine3.22cabbdfd2c3fe
openssl@3.5.5-1~deb13u2
3.5.6-1~deb13u2
1
quay.io/ortelius/ms-compitem-crud:main-v10.0.1566-gf3f81597b7f49eec76
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/ortelius/ms-dep-pkg-r:main-v10.0.1705-g21b3dc8a4150e94a45
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/ortelius/ms-textfile-crud:main-v10.0.1635-g5076aaf5c4c8adfc82
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/ortelius/ms-validate-user:main-v10.0.1694-g98ed94b5054bd4e97a
openssl@3.6.0-r6
3.6.3-r0
1
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
openssl@3.3.3-r0
3.3.7-r1
1
quay.io/reactiveops/rbac-manager:v1.9.587e3f461446f
openssl@3.5.4-r0
3.5.7-r0
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
openssl@3.5.6-r0
3.5.7-r0
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
openssl@3.3.3-r0
3.3.7-r1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
openssl@3.5.1-r0
3.5.7-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssl@3.0.9-1
3.0.20-1~deb12u2
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
openssl@1.1.1-1ubuntu2.1~18.04.17
1.1.1-1ubuntu2.1~18.04.23+esm9
1
registry.gitlab.com/dyff/dyff-frontend:0.20.2481be0beaafe
openssl@3.3.3-r0
3.3.7-r1
1
registry.gitlab.com/dyff/workflows-informer:0.4.4bfbadc49635d
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
openssl@3.5.5-1~deb13u1
3.5.6-1~deb13u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
openssl@3.0.13-1~deb12u1
3.0.20-1~deb12u2
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
openssl@3.5.6-r0
3.5.7-r0
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
openssl@3.5.6-r0
3.5.7-r0
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
openssl@1.1.1f-1ubuntu2.2
1.1.1f-1ubuntu2.24+esm4
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
openssl@3.3.7-r0
3.3.7-r1
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
openssl@3.3.7-r0
3.3.7-r1
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
openssl@3.0.20-1~deb12u1
3.0.20-1~deb12u2
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
openssl@3.5.5-r0
3.5.7-r0
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
openssl@3.5.5-r0
3.5.7-r0
1
registry.gitlab.com/technostructures/posca/posca:latesta693021686ca
openssl@3.5.6-r0
3.5.7-r0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
openssl@3.0.11-1~deb12u1
3.0.20-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
openssl@3.0.17-1~deb12u3
3.0.20-1~deb12u2
1
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
openssl@3.0.11-1~deb12u2
3.0.20-1~deb12u2
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
openssl@3.5.1-1
3.5.6-1~deb13u2
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
openssl@3.0.11-1~deb12u1
3.0.20-1~deb12u2
1
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
openssl@3.5.2-r0
3.5.7-r0
1
registry.k8s.io/ingress-nginx/controller:v1.13.137e489b22ac7
openssl@3.5.1-r0
3.5.7-r0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
openssl@3.3.2-r4
3.3.7-r1
1
registry.k8s.io/provider-os/manila-csi-plugin:v1.36.0190976e2e2fe
openssl@3.5.4-r0
3.5.7-r0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
openssl@3.0.15-1~deb12u1
3.0.20-1~deb12u2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.