StackRadar

CVE-2019-5481

Critical

Advisory

Published 11 Sept 2019In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.075
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
37
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 37 images.

Affected packageAffected versionsFixed inImages
curlapk7.57.0-r0, 7.58.0-r0, 7.59.0-r0, 7.60.0-r1+7 more7.61.1-r3, 7.64.0-r3, 7.66.0-r029
curldeb7.58.0-2ubuntu3.3, 7.58.0-2ubuntu3.5, 7.58.0-2ubuntu3.6, 7.58.0-2ubuntu3.77.58.0-2ubuntu3.88
OSV records
ALPINE-CVE-2019-5481UBUNTU-CVE-2019-5481
Also known as
USN-4129-1

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2019-5481.

Container imageDigestPackageFixed in
pstauffer/curl:latest2663156457ab
curl@7.60.0-r1
7.61.1-r3

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2019-5481.

Container imageDigestPackageFixed in
pstauffer/curl:latest2663156457ab
curl@7.60.0-r1
7.61.1-r3

Open the chart page →

20,462
consulsmo-helm-chart6.0.02 of 2See more

consul smo-helm-chart 6.0.0

2 of the 2 container images this version deploys carry CVE-2019-5481.

Container imageDigestPackageFixed in
library/consul:1.0.66ffe55dcc100
curl@7.58.0-r0
7.61.1-r3
oomk8s/consul:1.0.0ba60171909c7
curl@7.58.0-r0
7.61.1-r3

Open the chart page →

1,284
logrotatestakaterVerified publisher1.0.191 of 1See more

logrotate stakater 1.0.19

1 of the 1 container images this version deploys carry CVE-2019-5481.

Container imageDigestPackageFixed in
stakater/logrotate:3.13.05c0e01c23993
curl@7.57.0-r0
7.61.1-r3

Open the chart page →

1,011
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2019-5481.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
curl@7.61.1-r2
7.61.1-r3

Open the chart page →

1,572

Container images carrying it

37 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
appropriate/curl:latestc8bf5bbec639
curl@7.59.0-r0
7.61.1-r3
9
gradiant/hbase-base:2.0.1a1ee6de94c04
curl@7.61.1-r2
7.61.1-r3
4
anapsix/satisfyfae78e3809e9
curl@7.61.1-r2
7.61.1-r3
3
library/consul:1.6.194cdbd83f24e
curl@7.64.0-r2
7.64.0-r3
3
architectminds/aws-kubectl:1.19735e59a1085
curl@7.65.1-r0
7.66.0-r0
2
gitea/gitea:1.4146196cbc344
curl@7.60.0-r1
7.61.1-r3
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
curl@7.64.0-r2
7.64.0-r3
2
pstauffer/curl:latest2663156457ab
curl@7.60.0-r1
7.61.1-r3
2
weaveworks/scope:1.10.12887407cb701
curl@7.61.1-r1
7.61.1-r3
2
bpineau/katafygio:v0.7.176edd9d121b8
curl@7.60.0-r1
7.61.1-r3
1
daskdev/dask-notebook:1.1.0052630f5ca04
curl@7.58.0-2ubuntu3.5
7.58.0-2ubuntu3.8
1
fourcube/openiban:1.0.15091df635f7e
curl@7.61.0-r0
7.61.1-r3
1
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
curl@7.64.0-r1
7.64.0-r3
1
gocd/gocd-server:v19.3.02da45cb09d57
curl@7.64.0-r1
7.64.0-r3
1
hazelcast/hazelcast:3.11.2ca7d5589744f
curl@7.61.1-r1
7.61.1-r3
1
hazelcast/hazelcast-jet:3.0df495e64ea65
curl@7.64.0-r1
7.64.0-r3
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
curl@7.64.0-r2
7.64.0-r3
1
ibmcom/icp-storage-util:3.2.0c44e1ef21075
curl@7.64.0-r1
7.64.0-r3
1
ibmcom/skydive:0.22.0395e60cc6e3d
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.8
1
kubeaws/kube-spot-termination-notice-handler:1.13.0-1c9cd2ba4373a
curl@7.63.0-r0
7.64.0-r3
1
library/consul:1.0.66ffe55dcc100
curl@7.58.0-r0
7.61.1-r3
1
library/orientdb:3.0.1318a6c004398f
curl@7.63.0-r0
7.64.0-r3
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
curl@7.61.1-r1
7.61.1-r3
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.8
1
mintel/dex-k8s-authenticator:1.2.0a3789f95d734
curl@7.65.1-r0
7.66.0-r0
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.8
1
oomk8s/consul:1.0.0ba60171909c7
curl@7.58.0-r0
7.61.1-r3
1
opendatacube/pipelines:wofs-1.225d810e8504b8
curl@7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.8
1
opendatacube/restcube:latest91870111837c
curl@7.58.0-2ubuntu3.7
7.58.0-2ubuntu3.8
1
opendatacube/wms:latest1b90cdf68831
curl@7.58.0-2ubuntu3.7
7.58.0-2ubuntu3.8
1
runatlantis/atlantis:v0.7.168fa470d1416
curl@7.64.0-r1
7.64.0-r3
1
sismics/docs:v1.10f4b0ef019cf1
curl@7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.8
1
squareup/ghostunnel:v1.4.180674e1ec91c
curl@7.61.1-r2
7.61.1-r3
1
stakater/logrotate:3.13.05c0e01c23993
curl@7.57.0-r0
7.61.1-r3
1
tenstartups/ser2sock:latest379d9338c720
curl@7.64.0-r1
7.64.0-r3
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
curl@7.61.1-r2
7.61.1-r3
1
wiremind/sshd:latestb3d63ce7d198
curl@7.60.0-r1
7.61.1-r3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.