StackRadar

CVE-2018-16840

Critical

Advisory

Published 31 Oct 2018In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.034
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
curlapk7.59.0-r0, 7.60.0-r1, 7.61.0-r07.61.1-r110
OSV records
ALPINE-CVE-2018-16840

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
mattermost-team-editionmattermostVerified publisher6.6.1061 of 4See more

mattermost-team-edition mattermost 6.6.106

1 of the 4 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

1,475
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

8,722
mattermost-enterprise-editionmattermostVerified publisher2.6.1031 of 3See more

mattermost-enterprise-edition mattermost 2.6.103

1 of the 3 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

3,600
sshdwiremindVerified publisher0.1.11 of 1See more

sshd wiremind 0.1.1

1 of the 1 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
wiremind/sshd:latestb3d63ce7d198
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

1,171
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

9,808
katafygiocloudnativeapp0.4.01 of 1See more

katafygio cloudnativeapp 0.4.0

1 of the 1 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
bpineau/katafygio:v0.7.176edd9d121b8
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

893
openibancloudnativeapp1.0.01 of 1See more

openiban cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
fourcube/openiban:1.0.15091df635f7e
curl@7.61.0-r0
7.61.1-r1

Open the chart page →

922
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

11,174
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
curl@7.59.0-r0
7.61.1-r1
ibmcom/microclimate-portal:latested5505e5c7ec
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

57,669
giteajenkins-x1.3.121 of 3See more

gitea jenkins-x 1.3.12

1 of the 3 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
gitea/gitea:1.4146196cbc344
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

2,407
jx-app-giteajenkins-x0.0.21 of 3See more

jx-app-gitea jenkins-x 0.0.2

1 of the 3 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
gitea/gitea:1.4146196cbc344
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

2,407
knative-buildjenkins-x0.1.191 of 1See more

knative-build jenkins-x 0.1.19

1 of the 1 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
rawlingsj/build-controller:upstream306dd328e3d79
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

533
metricsjenkins-x0.0.61 of 9See more

metrics jenkins-x 0.0.6

1 of the 9 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

551
influxdblsst-sqre3.1.11 of 2See more

influxdb lsst-sqre 3.1.1

1 of the 2 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

758
sasquatchlsst-sqre0.1.131 of 6See more

sasquatch lsst-sqre 0.1.13

1 of the 6 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

9,332
mattermost-team-editionmattermost-team-edition6.6.831 of 4See more

mattermost-team-edition mattermost-team-edition 6.6.83

1 of the 4 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

4,089
mattermost-team-editionopenshift6.6.831 of 4See more

mattermost-team-edition openshift 6.6.83

1 of the 4 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1

Open the chart page →

4,089
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
pstauffer/curl:latest2663156457ab
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2018-16840.

Container imageDigestPackageFixed in
pstauffer/curl:latest2663156457ab
curl@7.60.0-r1
7.61.1-r1

Open the chart page →

20,462

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r1
9
gitea/gitea:1.4146196cbc344
curl@7.60.0-r1
7.61.1-r1
2
pstauffer/curl:latest2663156457ab
curl@7.60.0-r1
7.61.1-r1
2
bpineau/katafygio:v0.7.176edd9d121b8
curl@7.60.0-r1
7.61.1-r1
1
choerodon/event-store-service:0.8.03c94c97f6f69
curl@7.60.0-r1
7.61.1-r1
1
fourcube/openiban:1.0.15091df635f7e
curl@7.61.0-r0
7.61.1-r1
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
curl@7.59.0-r0
7.61.1-r1
1
ibmcom/microclimate-portal:latested5505e5c7ec
curl@7.59.0-r0
7.61.1-r1
1
rawlingsj/build-controller:upstream306dd328e3d79
curl@7.59.0-r0
7.61.1-r1
1
wiremind/sshd:latestb3d63ce7d198
curl@7.60.0-r1
7.61.1-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.