StackRadar

CVE-2023-38039

High

Advisory

Published 15 Sept 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.578
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
116
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
3 of 3
affected packages

curl-8.3.0-1.1 on GA media

Carried by container images the latest versions of 116 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+9 more8.3.0-r085
curldeb7.88.1-10, 7.88.1-10+deb12u17.88.1-10+deb12u320
curlrpm7.60.0-lp151.5.6.18.3.0-1.12
OSV records
ALPINE-CVE-2023-38039DEBIAN-CVE-2023-38039openSUSE-SU-2024:13230-1

Charts affected

116 by stars
ChartLatestAffected imagesRadar Score
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

16,620
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

12,668
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

2,449
serviceexampleserviceexample0.1.01 of 5See more

serviceexample serviceexample 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.3.0-r0

Open the chart page →

5,449
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

2,863
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.3.0-r0

Open the chart page →

4,285
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

20,223
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

12,460
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.3.0-r0
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.3.0-r0
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

21,005
posteetrivy-operator2.14.01 of 3See more

postee trivy-operator 2.14.0

1 of the 3 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

4,815
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

14,358
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.3.0-r0

Open the chart page →

2,030
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

5,033

Container images carrying it

107 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
iomesh/prepare-csi:v1.0.3-rc0063b18afb6a1
curl@8.1.2-r0
8.3.0-r0
1
iomesh/prepare-csi:v1.0.24206d42b92f1
curl@8.1.2-r0
8.3.0-r0
1
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
curl@8.2.1-r0
8.3.0-r0
1
kfirfer/king:latestc05d9fc7ae77
curl@8.2.1-r0
8.3.0-r0
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
curl@8.2.1-r0
8.3.0-r0
1
kyso/jupyter-diff:latest82299a9e5a86
curl@8.2.1-r0
8.3.0-r0
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
curl@7.86.0-r1
8.3.0-r0
1
library/nginx:1.25.167f9a4f10d14
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.3.0-r0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
curl@7.88.1-r1
8.3.0-r0
1
linuxserver/yq:3.2.26f5b9586a93e
curl@8.2.1-r0
8.3.0-r0
1
mantlenetworkio/l2geth:v0.4.36bf383d14291
curl@8.2.1-r0
8.3.0-r0
1
metabase/metabase:v0.46.09ebdc664a6b2
curl@7.88.1-r1
8.3.0-r0
1
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.3.0-r0
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
curl@8.1.2-r0
8.3.0-r0
1
phntom/chartmuseum:v0.16.053883b65d9b7
curl@8.2.0-r1
8.3.0-r0
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
curl@7.86.0-r1
8.3.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.23.17-nginx-3479ada675515f
curl@8.2.1-r0
8.3.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.22.17-nginx-34b85e437ae261
curl@8.2.1-r0
8.3.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.21.14-nginx-33fa8f5906d36a
curl@8.2.1-r0
8.3.0-r0
1
postgis/postgis:15-3.3-alpine4738bee21eb6
curl@8.2.1-r0
8.3.0-r0
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
curl@7.88.1-r1
8.3.0-r0
1
santisbon/speedtest:latest8ee3a1697227
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
shyim/shopware:6.4.6.0a951c0e6b836
curl@8.2.1-r0
8.3.0-r0
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
curl@8.2.1-r0
8.3.0-r0
1
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.3.0-r0
1
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.3.0-r0
1
thirtythreeforty/neolink:latestf564c4f538de
curl@8.0.1-r2
8.3.0-r0
1
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
udhos/forward:1.1.312e120d39fdb
curl@8.1.2-r0
8.3.0-r0
1
udhos/prime:1.0.0e432012dd34a
curl@8.1.2-r0
8.3.0-r0
1
vaultwarden/server:1.27.0-alpine7cd450642c54
curl@7.87.0-r0
8.3.0-r0
1
vlebediantsev/notes-admin-front:latest007c6670ff48
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
vlebediantsev/notes-project-front:latest945675fd2636
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
xvilo/php:8.2-composera138e57d3204
curl@7.87.0-r1
8.3.0-r0
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
curl@7.87.0-r1
8.3.0-r0
1
ghcr.io/data-fair/metrics:0a8d40779eeae
curl@8.1.2-r0
8.3.0-r0
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
curl@7.87.0-r1
8.3.0-r0
1
ghcr.io/k10app/businit:latest94c9a3e799c2
curl@7.86.0-r1
8.3.0-r0
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
curl@8.2.1-r0
8.3.0-r0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
curl@8.2.1-r0
8.3.0-r0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
curl@7.87.0-r2
8.3.0-r0
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
curl@8.0.1-r2
8.3.0-r0
1
ghcr.io/pascaliske/traefik-errors:1.1.00cf31753ce57
curl@8.1.2-r0
8.3.0-r0
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
curl@8.0.1-r0
8.3.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.