CVE-2022-32207
CriticalAdvisory
Published 27 Jun 2022In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.073
- 94th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 129
- of 17,781 indexed, latest versions
- Container images
- 122
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
The matching OSV records carry no description.
Carried by container images the latest versions of 129 of 17,781 indexed charts deploy, on 122 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 7.74.0-r0, 7.74.0-r1, 7.76.1-r0, 7.77.0-r0+7 more | 7.79.1-r2, 7.80.0-r2, 7.83.1-r2 | 119 |
| curldeb | 7.81.0-1ubuntu1.2 | 7.81.0-1ubuntu1.3 | 3 |
- OSV records
- ALPINE-CVE-2022-32207UBUNTU-CVE-2022-32207
- Also known as
- USN-5495-1
Charts affected
129 by stars
Container images carrying it
122 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| lachlanevenson/ | e4d83478963b | curl | 7.80.0-r2 | 3 |
| nginxinc/ | 084242d8028c | curl | 7.79.1-r2 | 3 |
| xenondb/ | 0241a1112566 | curl | 7.79.1-r2 | 3 |
| quay.io/ | 8e54bc2d261f | curl | 7.83.1-r2 | 3 |
| apteno/ | 74035b864eed | curl | 7.79.1-r2 | 2 |
| library/ | 07ab71a2c8e4 | curl | 7.79.1-r2 | 2 |
| svtechnmaa/ | b2987abe57d3 | curl | 7.81.0-1ubuntu1.3 | 2 |
| ghcr.io/ | 03fd01b4f56e | curl | 7.81.0-1ubuntu1.3 | 2 |
| quay.io/ | e98d13459cdc | curl | 7.80.0-r2 | 2 |
| quay.io/ | dc5d1ed91c26 | curl | 7.80.0-r2 | 2 |
| acockburn/ | 3a93281d7e94 | curl | 7.79.1-r2 | 1 |
| ajanvier/ | 91ac61b88c85 | curl | 7.79.1-r2 | 1 |
| alpine/ | 00ac10bcb759 | curl | 7.80.0-r2 | 1 |
| alpine/ | a41efe02a041 | curl | 7.79.1-r2 | 1 |
| ansiblesemaphore/ | 03d1f8684027 | curl | 7.79.1-r2 | 1 |
| apache/ | b4eabafa83cc | curl | 7.79.1-r2 | 1 |
| aquasec/ | 7ea4aa3d2eb6 | curl | 7.79.1-r2 | 1 |
| chaosnative/ | 07b82a82a702 | curl | 7.80.0-r2 | 1 |
| clastix/ | 87fabaccb3a6 | curl | 7.80.0-r2 | 1 |
| clastix/ | d0376d87ac6b | curl | 7.80.0-r2 | 1 |
| denisshav/ | b97cc69fbac6 | curl | 7.79.1-r2 | 1 |
| dniel/ | d3e38df449a2 | curl | 7.79.1-r2 | 1 |
| emqx/ | 1d36535ba9de | curl | 7.80.0-r2 | 1 |
| epamedp/ | 96028c86f0dd | curl | 7.79.1-r2 | 1 |
| epamedp/ | b71fb39e0c9e | curl | 7.79.1-r2 | 1 |
| factly/ | 140fbaa6d555 | curl | 7.79.1-r2 | 1 |
| factly/ | 0cf361b41798 | curl | 7.79.1-r2 | 1 |
| factly/ | 24be158ec7d3 | curl | 7.79.1-r2 | 1 |
| felddy/ | 6c5d90b90349 | curl | 7.79.1-r2 | 1 |
| filebrowser/ | 4fcd47af573c | curl | 7.79.1-r2 | 1 |
| gluufederation/ | 1a1128b28b95 | curl | 7.79.1-r2 | 1 |
| groundnuty/ | 84edcf796267 | curl | 7.80.0-r2 | 1 |
| ibarreche/ | e16a469c5791 | curl | 7.80.0-r2 | 1 |
| jesec/ | 3d1d0bec117a | curl | 7.79.1-r2 | 1 |
| jesec/ | 60bd59cfb4eb | curl | 7.79.1-r2 | 1 |
| jesec/ | f0c894ec459e | curl | 7.79.1-r2 | 1 |
| jfwenisch/ | 9e6c229f953c | curl | 7.79.1-r2 | 1 |
| johnblack77/ | bb53ceb8442e | curl | 7.79.1-r2 | 1 |
| jupyterhub/ | 723028bf9b3c | curl | 7.80.0-r2 | 1 |
| kanboard/ | 0b6d33dbbc16 | curl | 7.79.1-r2 | 1 |
| lavandadelpatio/ | ccfc0cd77803 | curl | 7.79.1-r2 | 1 |
| library/ | 143ec8cc2f3a | curl | 7.79.1-r2 | 1 |
| librenms/ | 4f1f3d667cc7 | curl | 7.80.0-r2 | 1 |
| longhornio/ | 148598de4b7d | curl | 7.79.1-r2 | 1 |
| longhornio/ | 65560eabe3ee | curl | 7.79.1-r2 | 1 |
| milesmcc/ | e821e31140f7 | curl | 7.79.1-r2 | 1 |
| moby/ | c2aeafaed434 | curl | 7.80.0-r2 | 1 |
| monogramm/ | 5afd99523984 | curl | 7.79.1-r2 | 1 |
| neilpang/ | 595809ad43a2 | curl | 7.80.0-r2 | 1 |
| nginxinc/ | 38d9dc79cc1d | curl | 7.79.1-r2 | 1 |