CVE-2022-27776
MediumAdvisory
Published 27 Apr 2022In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.038
- 89th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 469
- of 17,787 indexed, latest versions
- Container images
- 380
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 469 of 17,787 indexed charts deploy, on 380 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curldeb | 7.35.0-1ubuntu2.1, 7.35.0-1ubuntu2.3, 7.35.0-1ubuntu2.16, 7.35.0-1ubuntu2.19+30 more | 7.58.0-2ubuntu3.17, 7.68.0-1ubuntu2.10 | 197 |
| curlapk | 7.69.1-r0, 7.69.1-r1, 7.69.1-r3, 7.74.0-r0+7 more | 7.79.1-r1, 7.80.0-r1 | 183 |
- OSV records
- ALPINE-CVE-2022-27776UBUNTU-CVE-2022-27776
- Also known as
- USN-5397-1
Charts affected
469 by stars
Container images carrying it
380 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| streamnative/ | 11bceacec8fb | curl | 7.68.0-1ubuntu2.10 | 1 |
| t3nde/ | 329ce194393a | curl | 7.79.1-r1 | 1 |
| taemon1337/ | 247bc1dc4f07 | curl | 7.80.0-r1 | 1 |
| taemon1337/ | e8f5096c66bb | curl | 7.80.0-r1 | 1 |
| taigaio/ | 4d367b1e1250 | curl | 7.79.1-r1 | 1 |
| temporalio/ | 35034611d981 | curl | 7.79.1-r1 | 1 |
| temporalio/ | e26758f5a1bf | curl | 7.79.1-r1 | 1 |
| tensorflow/ | 1e3172090703 | curl | no fix listed | 1 |
| timescale/ | 7758704d4a14 | curl | 7.79.1-r1 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | curl | no fix listed | 1 |
| tomsquest/ | 4759cc353a1d | curl | 7.79.1-r1 | 1 |
| tpdock/ | 3da600c95a49 | curl | no fix listed | 1 |
| trafex/ | 7282edfca2bf | curl | 7.79.1-r1 | 1 |
| trafex/ | ee0b7c6cce07 | curl | 7.79.1-r1 | 1 |
| vectorim/ | 080e313abd37 | curl | 7.79.1-r1 | 1 |
| vectorim/ | 234bed2ac92a | curl | 7.79.1-r1 | 1 |
| vectorim/ | 84bb5af00b5d | curl | 7.79.1-r1 | 1 |
| vitorbari/ | fd3ccb820ada | curl | 7.79.1-r1 | 1 |
| voltha/ | 59ab2a00f712 | curl | no fix listed | 1 |
| wallabag/ | 5e4c26a7fb4a | curl | 7.79.1-r1 | 1 |
| wavefronthq/ | d1064d28f6eb | curl | 7.58.0-2ubuntu3.17 | 1 |
| weetmuts/ | a79967400c61 | curl | 7.79.1-r1 | 1 |
| wener/ | ef3bd19da190 | curl | 7.79.1-r1 | 1 |
| wener/ | cc9fd4da44c0 | curl | 7.79.1-r1 | 1 |
| wener/ | 5c92cc9e8597 | curl | 7.79.1-r1 | 1 |
| wener/ | 9a42bae466d4 | curl | 7.79.1-r1 | 1 |
| zabbix/ | 2127168cab03 | curl | 7.68.0-1ubuntu2.10 | 1 |
| zabbix/ | 6c946b1f45cd | curl | 7.68.0-1ubuntu2.10 | 1 |
| zabbix/ | 01de79c31391 | curl | 7.68.0-1ubuntu2.10 | 1 |
| gcr.io/ | 809338a69bd5 | curl | 7.58.0-2ubuntu3.17 | 1 |
| gcr.io/ | 10f4dbc8eeeb | curl | no fix listed | 1 |
| gcr.io/ | cb5c1bddd1b5 | curl | no fix listed | 1 |
| gcr.io/ | 5ea7b7f3632a | curl | no fix listed | 1 |
| gcr.io/ | c552478f8f11 | curl | 7.68.0-1ubuntu2.10 | 1 |
| gcr.io/ | 8f9ff98fdbef | curl | no fix listed | 1 |
| gcr.io/ | 9538fabe49fd | curl | 7.68.0-1ubuntu2.10 | 1 |
| gcr.io/ | 96dfb19838b8 | curl | 7.79.1-r1 | 1 |
| gcr.io/ | ba66607c947c | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | 0147d87c2019 | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | c5075f0320cd | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | 94a749392fcf | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | ee6a21e66ff0 | curl | 7.80.0-r1 | 1 |
| ghcr.io/ | c17f1ba17d36 | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | eeb625bd660c | curl | 7.80.0-r1 | 1 |
| ghcr.io/ | 03aba499950f | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | 24bbca4a52a8 | curl | 7.80.0-r1 | 1 |
| ghcr.io/ | da6b05a1a601 | curl | 7.80.0-r1 | 1 |
| ghcr.io/ | deed102b4255 | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | 35225eaa87ab | curl | 7.79.1-r1 | 1 |
| ghcr.io/ | 4ffe222b3e3a | curl | 7.79.1-r1 | 1 |