StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/bentoml/yatai:0.4.614b482c1f1b8
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
curl@7.83.1-r1
8.5.0-r0
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
curl@7.58.0-2ubuntu3.20
7.58.0-2ubuntu3.24+esm3
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
curl@8.1.0-r0
8.5.0-r0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
curl@7.81.0-1ubuntu1.6
7.81.0-1ubuntu1.15
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u11
1
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
curl@7.83.1-r4
8.5.0-r0
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
curl@7.47.0-1ubuntu2.16
7.47.0-1ubuntu2.19+esm11
1
quay.io/netwarps/blockscoutbecd3e39360a
curl@7.80.0-r0
8.5.0-r0
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
curl@7.80.0-r0
8.5.0-r0
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
curl@8.0.1-r0
8.5.0-r0
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
curl@7.83.1-r3
8.5.0-r0
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
curl@7.47.0-1ubuntu2.18
7.47.0-1ubuntu2.19+esm11
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
curl@7.76.1-23.el9_2.2
0:7.76.1-23.el9_2.6
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
curl@7.88.1-10+deb12u1
7.88.1-10+deb12u5
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
curl@7.87.0-r1
8.5.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
curl@7.83.1-r3
8.5.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.5.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
curl@7.88.1-r1
8.5.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
curl@7.83.1-r2
8.5.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.