StackRadar

CVE-2020-8286

High

Advisory

Published 9 Dec 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.046
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
258
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 258 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
curlapk7.65.1-r0, 7.66.0-r0, 7.67.0-r0, 7.67.0-r1+2 more7.66.0-r3, 7.67.0-r3, 7.69.1-r391
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+15 more7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.471
OSV records
ALPINE-CVE-2020-8286UBUNTU-CVE-2020-8286
Also known as
USN-4665-1

Charts affected

258 by stars
ChartLatestAffected imagesRadar Score
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

7,429
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12

Open the chart page →

20,190
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12

Open the chart page →

20,190
alpinewenerme1.0.01 of 1See more

alpine wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
wener/base:3.12.0ef3bd19da190
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

1,263
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
curl@7.69.1-r1
7.69.1-r3

Open the chart page →

10,127
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.12

Open the chart page →

10,843
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
curl@7.67.0-r0
7.67.0-r3

Open the chart page →

3,424
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2020-8286.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
curl@7.69.1-r0
7.69.1-r3

Open the chart page →

1,198

Container images carrying it

162 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opendatacube/wms:latest1b90cdf68831
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
openwhisk/invoker:1.0.0f5831ec85525
curl@7.69.1-r1
7.69.1-r3
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.12
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
curl@7.47.0-1ubuntu2.15
7.47.0-1ubuntu2.18
1
pnnlmiscscripts/anaconda:20200421-1700-nginx-1bbb6940d849f
curl@7.67.0-r0
7.67.0-r3
1
pnnlmiscscripts/k8s-node-image:1.14.10-nginx-78af4c559fff0
curl@7.67.0-r0
7.67.0-r3
1
pnnlmiscscripts/k8s-node-image:1.15.12-nginx-5d710d31000ce
curl@7.67.0-r1
7.67.0-r3
1
pozetroninc/keydb:v6.0.1653ae64f29da8
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.12
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
curl@7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.18
1
runatlantis/atlantis:v0.16.145fbaf7e207c
curl@7.69.1-r0
7.69.1-r3
1
rundeck/rundeck:3.2.74d64fe56f767
curl@7.47.0-1ubuntu2.14
7.47.0-1ubuntu2.18
1
rundeck/rundeck:3.0.16b13e8059ad72
curl@7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.18
1
scrapinghub/splash:3.4.1a5f89bc84606
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
seldonio/locust-core:0.81d0da98a2d76
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.18
1
sismics/docs:v1.10f4b0ef019cf1
curl@7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.12
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.18
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.18
1
tpdock/freeradius:2.2.93da600c95a49
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.18
1
vectorim/riot-web:v1.7.8080e313abd37
curl@7.69.1-r0
7.69.1-r3
1
wavefronthq/proxy:9.2d1064d28f6eb
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.12
1
wener/base:3.12.0ef3bd19da190
curl@7.69.1-r0
7.69.1-r3
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.12
1
gcr.io/google-containers/echoserver:1.910f4dbc8eeeb
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.18
1
gcr.io/google_containers/echoserver:1.10cb5c1bddd1b5
curl@7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.18
1
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.18
1
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
curl@7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.18
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
curl@7.67.0-r0
7.67.0-r3
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
curl@7.69.1-r1
7.69.1-r3
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
curl@7.69.1-r0
7.69.1-r3
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
curl@7.69.1-r0
7.69.1-r3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.