StackRadar

CVE-2019-5436

High

Advisory

Published 22 May 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.497
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
112
of 17,781 indexed, latest versions
Container images
97
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security and bug fix update

Carried by container images the latest versions of 112 of 17,781 indexed charts deploy, on 97 images.

Affected packageAffected versionsFixed inImages
curldeb7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16, 7.35.0-1ubuntu2.19+20 more7.35.0-1ubuntu2.20+esm2, 7.38.0-4+deb8u15, 7.47.0-1ubuntu2.13, 7.58.0-2ubuntu3.773
curlapk7.63.0-r0, 7.64.0-r17.64.0-r28
curlrpm7.29.0-51.el7, 7.29.0-51.el7_6.3, 7.29.0-54.el7, 7.29.0-54.el7_7.20:7.29.0-57.el716
OSV records
ALPINE-CVE-2019-5436RHSA-2020:1020UBUNTU-CVE-2019-5436DLA-1804-1
Also known as
RHSA-2020:2505, USN-3993-1, USN-3993-2

Charts affected

112 by stars
ChartLatestAffected imagesRadar Score
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
curl@7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.13

Open the chart page →

27,477
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

25,769
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15

Open the chart page →

3,116
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.13

Open the chart page →

11,007
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13

Open the chart page →

15,330
Wordressuvaise-wordpress0.2.01 of 2See more

Wordress uvaise-wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
curl@7.38.0-4+deb8u7
7.38.0-4+deb8u15

Open the chart page →

1,339
Wordresswordpress0.2.01 of 2See more

Wordress wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-5436.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
curl@7.38.0-4+deb8u7
7.38.0-4+deb8u15

Open the chart page →

1,339

Container images carrying it

97 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
curl@7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.13
1
ibmcom/icp-storage-util:3.2.0c44e1ef21075
curl@7.64.0-r1
7.64.0-r2
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
curl@7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.13
1
ibmcom/microclimate-theia:lateste17bdccc5030
curl@7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.13
1
ibmcom/skydive:0.22.0395e60cc6e3d
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.7
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
curl@7.29.0-54.el7_7.2
0:7.29.0-57.el7
1
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
curl@7.29.0-54.el7
0:7.29.0-57.el7
1
jacobalberty/unifi:5.10.19c409924e2463
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13
1
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
curl@7.63.0-r0
7.64.0-r2
1
kubedex/helm-controller:v1.0.14f1008c51ef9
curl@7.29.0-51.el7_6.3
0:7.29.0-57.el7
1
library/orientdb:3.0.1318a6c004398f
curl@7.63.0-r0
7.64.0-r2
1
library/percona:5.7.17d5d7f368de4a
curl@7.38.0-4+deb8u5
7.38.0-4+deb8u15
1
lightbend/curl:7.47.0b0c9894ac8dd
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.13
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.7
1
muluder/prograncontrollermcord:0.1.843b597a93da7
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.13
1
ncsapolyglot/converters-openjpeg:latest2ba4af461d51
curl@7.38.0-4+deb8u5
7.38.0-4+deb8u15
1
neilpeterson/get-tweet:v28b645ac1a23e
curl@7.38.0-4+deb8u10
7.38.0-4+deb8u15
1
neilpeterson/osba-container-instances-demo:latest6527b05d5d03
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15
1
neilpeterson/osba-cosmos-mongodb-demo:latestf4940e84ed05
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15
1
neilpeterson/osba-mysql-demo:latest5859d68a6c9f
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15
1
neilpeterson/osba-storage-demo:latest29d229ab446e
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15
1
neilpeterson/osba-text-analytics-demo:latest969af3cb8466
curl@7.38.0-4+deb8u10
7.38.0-4+deb8u15
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.7
1
omecproject/onos-progran:1.0.05715e5648aa0
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.13
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13
1
opendatacube/pipelines:wofs-1.225d810e8504b8
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.7
1
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
curl@7.29.0-54.el7
0:7.29.0-57.el7
1
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
curl@7.29.0-54.el7
0:7.29.0-57.el7
1
opsmx11/issuegen:v2.1.05c50ca123d88
curl@7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.20+esm2
1
percona/percona-xtradb-cluster:5.7.19eaa3fcb7a5a2
curl@7.38.0-4+deb8u6
7.38.0-4+deb8u15
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
curl@7.38.0-4+deb8u4
7.38.0-4+deb8u15
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.13
1
resouer/redis-slave:v2e2f198b49ba7
curl@7.35.0-1ubuntu2.3
7.35.0-1ubuntu2.20+esm2
1
runatlantis/atlantis:v0.7.168fa470d1416
curl@7.64.0-r1
7.64.0-r2
1
rundeck/rundeck:3.0.16b13e8059ad72
curl@7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.13
1
sismics/docs:v1.10f4b0ef019cf1
curl@7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.7
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.13
1
tenstartups/ser2sock:latest379d9338c720
curl@7.64.0-r1
7.64.0-r2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.13
1
timothyclarke/wptserver:2018-03-0840a80ced8031
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u15
1
tpdock/freeradius:2.2.93da600c95a49
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.13
1
voltha/voltha-envoy:1.6.059ab2a00f712
curl@7.35.0-1ubuntu2.19
7.35.0-1ubuntu2.20+esm2
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
curl@7.38.0-4+deb8u10
7.38.0-4+deb8u15
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.13
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.13
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
curl@7.38.0-4+deb8u10
7.38.0-4+deb8u15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.