StackRadar

CVE-2019-5482

Critical

Advisory

Published 11 Sept 2019In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.179
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 17,781 indexed, latest versions
Container images
128
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 157 of 17,781 indexed charts deploy, on 128 images.

Affected packageAffected versionsFixed inImages
curldeb7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16, 7.35.0-1ubuntu2.19+22 more7.35.0-1ubuntu2.20+esm3, 7.38.0-4+deb8u16, 7.47.0-1ubuntu2.14, 7.58.0-2ubuntu3.881
curlapk7.57.0-r0, 7.58.0-r0, 7.59.0-r0, 7.60.0-r1+7 more7.61.1-r3, 7.64.0-r3, 7.66.0-r029
curlrpm7.29.0-51.el7, 7.29.0-51.el7_6.3, 7.29.0-54.el7, 7.29.0-54.el7_7.2+1 more0:7.29.0-59.el718
OSV records
ALPINE-CVE-2019-5482UBUNTU-CVE-2019-5482RHSA-2020:3916DLA-1917-1
Also known as
RHSA-2021:0877, RHSA-2021:1027, USN-4129-1, USN-4129-2

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
logrotatestakaterVerified publisher1.0.191 of 1See more

logrotate stakater 1.0.19

1 of the 1 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
stakater/logrotate:3.13.05c0e01c23993
curl@7.57.0-r0
7.61.1-r3

Open the chart page →

1,011
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u16

Open the chart page →

3,116
standard-applicationthebitgram1.0.121 of 1See more

standard-application thebitgram 1.0.12

1 of the 1 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.14

Open the chart page →

11,007
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.14

Open the chart page →

15,330
Wordressuvaise-wordpress0.2.01 of 2See more

Wordress uvaise-wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
curl@7.38.0-4+deb8u7
7.38.0-4+deb8u16

Open the chart page →

1,339
Wordresswordpress0.2.01 of 2See more

Wordress wordpress 0.2.0

1 of the 2 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
library/wordpress:4.8-apache6216f64ab88f
curl@7.38.0-4+deb8u7
7.38.0-4+deb8u16

Open the chart page →

1,339
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2019-5482.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
curl@7.61.1-r2
7.61.1-r3

Open the chart page →

1,572

Container images carrying it

128 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
curl@7.29.0-54.el7
0:7.29.0-59.el7
1
opsmx11/issuegen:v2.1.05c50ca123d88
curl@7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.20+esm3
1
percona/percona-xtradb-cluster:5.7.19eaa3fcb7a5a2
curl@7.38.0-4+deb8u6
7.38.0-4+deb8u16
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
curl@7.38.0-4+deb8u4
7.38.0-4+deb8u16
1
rancher/hardened-calico:v3.13.36d2cd61a338b
curl@7.29.0-57.el7_8.1
0:7.29.0-59.el7
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.14
1
resouer/redis-slave:v2e2f198b49ba7
curl@7.35.0-1ubuntu2.3
7.35.0-1ubuntu2.20+esm3
1
runatlantis/atlantis:v0.7.168fa470d1416
curl@7.64.0-r1
7.64.0-r3
1
rundeck/rundeck:3.0.16b13e8059ad72
curl@7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.14
1
seldonio/locust-core:0.81d0da98a2d76
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.14
1
sismics/docs:v1.10f4b0ef019cf1
curl@7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.8
1
squareup/ghostunnel:v1.4.180674e1ec91c
curl@7.61.1-r2
7.61.1-r3
1
stakater/logrotate:3.13.05c0e01c23993
curl@7.57.0-r0
7.61.1-r3
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u16
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.14
1
tenstartups/ser2sock:latest379d9338c720
curl@7.64.0-r1
7.64.0-r3
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.14
1
timothyclarke/wptserver:2018-03-0840a80ced8031
curl@7.38.0-4+deb8u9
7.38.0-4+deb8u16
1
tpdock/freeradius:2.2.93da600c95a49
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.14
1
voltha/voltha-envoy:1.6.059ab2a00f712
curl@7.35.0-1ubuntu2.19
7.35.0-1ubuntu2.20+esm3
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
curl@7.61.1-r2
7.61.1-r3
1
wiremind/sshd:latestb3d63ce7d198
curl@7.60.0-r1
7.61.1-r3
1
zenko/zenko-cosbench:0.0.6386a1f48ec0e
curl@7.38.0-4+deb8u10
7.38.0-4+deb8u16
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.14
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.14
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.14
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.14
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
curl@7.38.0-4+deb8u10
7.38.0-4+deb8u16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.