StackRadar

CVE-2023-38039

High

Advisory

Published 15 Sept 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.578
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
116
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
3 of 3
affected packages

curl-8.3.0-1.1 on GA media

Carried by container images the latest versions of 116 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+9 more8.3.0-r085
curldeb7.88.1-10, 7.88.1-10+deb12u17.88.1-10+deb12u320
curlrpm7.60.0-lp151.5.6.18.3.0-1.12
OSV records
ALPINE-CVE-2023-38039DEBIAN-CVE-2023-38039openSUSE-SU-2024:13230-1

Charts affected

116 by stars
ChartLatestAffected imagesRadar Score
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

16,620
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

12,668
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

2,449
serviceexampleserviceexample0.1.01 of 5See more

serviceexample serviceexample 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.3.0-r0

Open the chart page →

5,449
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

2,863
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.3.0-r0

Open the chart page →

4,285
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

20,223
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0

Open the chart page →

12,460
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.3.0-r0
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.3.0-r0
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

21,005
posteetrivy-operator2.14.01 of 3See more

postee trivy-operator 2.14.0

1 of the 3 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

4,815
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3

Open the chart page →

14,358
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u3

Open the chart page →

10,001
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.3.0-r0

Open the chart page →

2,030
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-38039.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.3.0-r0

Open the chart page →

5,033

Container images carrying it

107 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.3.0-r0
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
curl@7.88.1-10
7.88.1-10+deb12u3
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
curl@8.1.2-r0
8.3.0-r0
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.3.0-r0
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
curl@8.2.1-r0
8.3.0-r0
2
cs3org/wopiserver:v9.4.202a9e78757b4
curl@7.88.1-r0
8.3.0-r0
2
daniacobext/airports-frontend:latest9eae4d39fc33
curl@8.1.2-r0
8.3.0-r0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
curl@7.88.1-10
7.88.1-10+deb12u3
2
krtk6160/galoy-nostrcc82a694f818
curl@7.87.0-r2
8.3.0-r0
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
curl@8.2.1-r0
8.3.0-r0
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
curl@7.86.0-r1
8.3.0-r0
2
library/influxdb:2.6.1-alpine44a366dd7724
curl@7.88.1-r1
8.3.0-r0
2
library/python:3.7eedf63967cdb
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
2
metabase/metabase:v0.45.21fb334ce4820
curl@7.87.0-r1
8.3.0-r0
2
taigaio/taiga-front:latest570c8792ce80
curl@7.88.1-r1
8.3.0-r0
2
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.3.0-r0
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.3.0-r0
2
akaunting/akaunting:3.0.1552811b36ec3a
curl@7.88.1-10
7.88.1-10+deb12u3
1
alpine/k8s:1.27.321b24e6bf801
curl@8.1.2-r0
8.3.0-r0
1
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.3.0-r0
1
aquasec/trivy:0.43.1944a04445179
curl@8.1.2-r0
8.3.0-r0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
avinash263/pyredis263:latestaa2b8727f1a6
curl@7.88.1-10
7.88.1-10+deb12u3
1
casbin/casdoor:v1.224.066f836ef778b
curl@7.87.0-r1
8.3.0-r0
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
curl@7.60.0-lp151.5.6.1
8.3.0-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
curl@7.60.0-lp151.5.6.1
8.3.0-1.1
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
curl@8.1.2-r0
8.3.0-r0
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
curl@7.87.0-r0
8.3.0-r0
1
devopstales/trivy-operator:2.575136aa7a26e
curl@7.87.0-r1
8.3.0-r0
1
dnsforge/xteve:latest4d9a685c8c28
curl@7.87.0-r1
8.3.0-r0
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
curl@7.88.1-r0
8.3.0-r0
1
emqx/emqx:4.4.1971db5ed95db3
curl@8.1.2-r0
8.3.0-r0
1
factly/mande-studio:0.34.19db4bee30e63
curl@8.2.1-r0
8.3.0-r0
1
fedodo/fedodo.ui.home:3c69413c4d690
curl@8.1.2-r0
8.3.0-r0
1
fedodo/fedodo.ui.micro:12b2b540081c21
curl@8.1.2-r0
8.3.0-r0
1
felipecs8/qrcode-generator:v1d5f4f17cb066
curl@7.87.0-r1
8.3.0-r0
1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
curl@8.1.2-r0
8.3.0-r0
1
folioci/mod-data-import-converter-storage:latest3028f333778f
curl@7.87.0-r0
8.3.0-r0
1
glenndehaan/sunflare-tools:latesta5b3f1dd865d
curl@8.2.1-r0
8.3.0-r0
1
grafana/grafana:10.1.11b9ca4bbc4a2
curl@8.2.1-r0
8.3.0-r0
1
grafana/grafana:9.5.239c849cebccc
curl@8.0.1-r0
8.3.0-r0
1
gulacedia/web-dvwa-new:v367b467d961ca
curl@7.88.1-10
7.88.1-10+deb12u3
1
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.3.0-r0
1
hashicorp/terraform:1.44dcb45513699
curl@8.2.1-r0
8.3.0-r0
1
hashicorp/waypoint:0.11.397d521a27498
curl@8.1.2-r0
8.3.0-r0
1
hazelcast/hazelcast:5.3.18fe26efde8e1
curl@8.2.1-r0
8.3.0-r0
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
curl@8.1.2-r0
8.3.0-r0
1
i4trust/activation-service:2.2.09f3719176893
curl@8.1.2-r0
8.3.0-r0
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u3
1
invoiceninja/invoiceninja:5.6.241437916dee01
curl@8.1.2-r0
8.3.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.