StackRadar

CVE-2023-38039

High

Advisory

Published 15 Sept 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.578
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
116
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
3 of 3
affected packages

curl-8.3.0-1.1 on GA media

Carried by container images the latest versions of 116 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+9 more8.3.0-r085
curldeb7.88.1-10, 7.88.1-10+deb12u17.88.1-10+deb12u320
curlrpm7.60.0-lp151.5.6.18.3.0-1.12
OSV records
ALPINE-CVE-2023-38039DEBIAN-CVE-2023-38039openSUSE-SU-2024:13230-1

Charts affected

116 by stars
ChartLatestAffected imagesRadar Score
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

16,620
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

12,668
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

2,449
serviceexampleserviceexample0.1.01 of 5See more

serviceexample serviceexample 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.3.0-r0

Open the chart page →

5,449
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

2,863
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.3.0-r0

Open the chart page →

4,285
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

20,223
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

12,460
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.3.0-r0
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.3.0-r0
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

21,005
posteetrivy-operator2.14.01 of 3See more

postee trivy-operator 2.14.0

1 of the 3 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

4,815
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

14,358
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.3.0-r0

Open the chart page →

2,030
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

5,033

Container images carrying it

107 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
curl@8.1.0-r0
8.3.0-r0
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
curl@8.0.1-r0
8.3.0-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
curl@7.87.0-r1
8.3.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.3.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
curl@7.88.1-r1
8.3.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.