StackRadar

CVE-2021-22898

Low

Advisory

Published 26 May 2021In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.045
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
366
of 17,781 indexed, latest versions
Container images
263
deployed by those charts
Fix available
3 of 3
affected packages

Security update for curl

Carried by container images the latest versions of 366 of 17,781 indexed charts deploy, on 263 images.

Affected packageAffected versionsFixed inImages
curlrpm7.66.0-4.6.17.66.0-4.17.11
curlapk7.65.1-r0, 7.66.0-r0, 7.66.0-r3, 7.67.0-r0+8 more7.66.0-r4, 7.67.0-r4, 7.77.0-r0139
curldeb7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16, 7.35.0-1ubuntu2.19+26 more7.35.0-1ubuntu2.20+esm14, 7.47.0-1ubuntu2.19+esm3, 7.58.0-2ubuntu3.14, 7.68.0-1ubuntu2.6123
OSV records
ALPINE-CVE-2021-22898UBUNTU-CVE-2021-22898SUSE-SU-2021:1762-1
Also known as
USN-5021-1, USN-5021-2, USN-5894-1

Charts affected

366 by stars
ChartLatestAffected imagesRadar Score
lightstepupdater-lightstep-satellite1.2.21 of 1See more

lightstep updater-lightstep-satellite 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
curl@7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.19+esm3

Open the chart page →

15,330
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
curl@7.69.1-r0
7.77.0-r0

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
curl@7.69.1-r0
7.77.0-r0

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
curl@7.69.1-r0
7.77.0-r0

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
curl@7.69.1-r0
7.77.0-r0

Open the chart page →

7,429
pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.6
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.14

Open the chart page →

20,190
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.6
flyway/flyway:6.4.422d97ceb0c47
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.14

Open the chart page →

20,190
alpinewenerme1.0.01 of 1See more

alpine wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
wener/base:3.12.0ef3bd19da190
curl@7.69.1-r0
7.77.0-r0

Open the chart page →

1,263
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
curl@7.67.0-r3
7.67.0-r4

Open the chart page →

4,984
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
curl@7.69.1-r1
7.77.0-r0

Open the chart page →

10,127
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.14

Open the chart page →

10,843
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
curl@7.74.0-r0
7.77.0-r0

Open the chart page →

2,555
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
curl@7.66.0-r3
7.66.0-r4

Open the chart page →

2,745
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
curl@7.66.0-r3
7.66.0-r4

Open the chart page →

2,791
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
curl@7.67.0-r0
7.67.0-r4

Open the chart page →

3,424
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2021-22898.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
curl@7.69.1-r0
7.77.0-r0

Open the chart page →

1,198

Container images carrying it

263 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/ttyd:latestd79c1c5881c0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.14
1
conduction/agendaservice-php:latest9cfeeb6c7c20
curl@7.69.1-r0
7.77.0-r0
1
conduction/balance-registration-php:devc36094a41369
curl@7.69.1-r0
7.77.0-r0
1
conduction/betaalservice-php:latestece1ab544c57
curl@7.69.1-r0
7.77.0-r0
1
conduction/cgrc-php:dev25415534d245
curl@7.67.0-r0
7.67.0-r4
1
conduction/checkin-component-php:dev3423845692c1
curl@7.69.1-r0
7.77.0-r0
1
conduction/conduction-ui-php:dev2744565516e8
curl@7.69.1-r0
7.77.0-r0
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
curl@7.69.1-r0
7.77.0-r0
1
conduction/docparser-php:devb6f95c8ead7d
curl@7.69.1-r0
7.77.0-r0
1
conduction/kvk-php:dev8f177f9f8a7b
curl@7.69.1-r0
7.77.0-r0
1
conduction/pan-php:dev24f03c57568f
curl@7.69.1-r0
7.77.0-r0
1
cribl/cribl:3.0.2762747cb6796
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.14
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
curl@7.47.0-1ubuntu2.19
7.47.0-1ubuntu2.19+esm3
1
daskdev/dask-notebook:1.1.0052630f5ca04
curl@7.58.0-2ubuntu3.5
7.58.0-2ubuntu3.14
1
datalust/seq:5.0.832-pre9c731bb207a6
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.19+esm3
1
datawire/aes:1.13.62beb65062c8b
curl@7.76.1-r0
7.77.0-r0
1
dellcloud/category:distributed02fc234353a9
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.6
1
dellcloud/pages:1.04d2eb25b9225
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.6
1
denisshav/frontend:latestb97cc69fbac6
curl@7.76.1-r0
7.77.0-r0
1
devspacecloud/auth:0.3.39ccfe38b31b5
curl@7.67.0-r0
7.67.0-r4
1
devspacecloud/manager:0.3.349c397413f7b
curl@7.67.0-r0
7.67.0-r4
1
dniel/api-posts:master45a667852f2a
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.14
1
elastictranscoder/media:627e21dc963ab3858c6b
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.14
1
elastictranscoder/media-storage:f6d861a026208b8c2359
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.14
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.14
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.14
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.19+esm3
1
felddy/foundryvtt:0.8.36c5d90b90349
curl@7.76.1-r0
7.77.0-r0
1
folioci/mod-marccat:latest1b57d690d568
curl@7.66.0-r0
7.66.0-r4
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.14
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.14
1
free5gmano/nextepc-mongodb:latest36f806935519
curl@7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.19+esm3
1
galaxy/galaxy-init:v18.010267bad550e6
curl@7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.20+esm14
1
galaxy/galaxy-stable:v18.018e577a626dfd
curl@7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.20+esm14
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.14
1
gethue/hue:4.10.05702b2c37ff9
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.14
1
gitea/gitea:1.12.485416d6f65fe
curl@7.67.0-r0
7.67.0-r4
1
gitea/gitea:1.13.0d5ab14cd29af
curl@7.69.1-r1
7.77.0-r0
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
curl@7.69.1-r0
7.77.0-r0
1
gmelillo/bind9:latesteeb2f9371b71
curl@7.69.1-r3
7.77.0-r0
1
gmelillo/nginx:2021-01-091b30f79cf7ea
curl@7.69.1-r3
7.77.0-r0
1
gogs/gogs:0.12.30195b095d0b2
curl@7.67.0-r0
7.67.0-r4
1
gogs/gogs:0.12.1420d53bb7277
curl@7.67.0-r0
7.67.0-r4
1
golenski/fibonacci-front:2.0.048cfd60b8413
curl@7.69.1-r0
7.77.0-r0
1
gomods/athens:v0.8.1d714c7ff0231
curl@7.67.0-r0
7.67.0-r4
1
gomods/athens:v0.11.0efb811df7844
curl@7.67.0-r3
7.67.0-r4
1
gotson/komga:0.99.49b15ea6bfc30
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.14
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
curl@7.69.1-r0
7.77.0-r0
1
hashicorp/vault-k8s:0.6.05697b85bc69a
curl@7.69.1-r1
7.77.0-r0
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.