StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,790 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,790 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,084
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,047
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
curl@7.76.1-19.el9
0:7.76.1-26.el9_3.3
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
curl@7.58.0-2ubuntu3.14
7.58.0-2ubuntu3.24+esm3
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
curl@7.68.0-1ubuntu2.14
7.68.0-1ubuntu2.21
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
curl@7.87.0-r1
8.5.0-r0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
curl@8.4.0-r0
8.5.0-r0
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
curl@7.58.0-2ubuntu3.24
7.58.0-2ubuntu3.24+esm3
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/k10app/businit:latest94c9a3e799c2
curl@7.86.0-r1
8.5.0-r0
1
ghcr.io/k10app/frontend:latest066b5ac6b119
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/k10app/staticcache:lateste77805689a8e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
curl@7.68.0-1ubuntu2.10
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
curl@7.81.0-1ubuntu1.3
7.81.0-1ubuntu1.15
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/theme-park:v1.7.3f8a5ec8f4669
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
curl@7.68.0-1ubuntu2.5
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
curl@7.68.0-1ubuntu2.18
7.68.0-1ubuntu2.21
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
curl@7.83.1-r1
8.5.0-r0
1
ghcr.io/kiaedev/kiae:latestebd03028ff6a
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
curl@7.58.0-2ubuntu3.21
7.58.0-2ubuntu3.24+esm3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
curl@7.68.0-1ubuntu2.6
7.68.0-1ubuntu2.21
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.