StackRadar

CVE-2023-46218

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
904
of 17,787 indexed, latest versions
Container images
826
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 904 of 17,787 indexed charts deploy, on 826 images.

Affected packageAffected versionsFixed inImages
curldeb7.47.0-1ubuntu2.2, 7.47.0-1ubuntu2.5, 7.47.0-1ubuntu2.6, 7.47.0-1ubuntu2.7+61 more7.47.0-1ubuntu2.19+esm11, 7.58.0-2ubuntu3.24+esm3, 7.68.0-1ubuntu2.21, 7.74.0-1.3+deb11u11+2 more588
curlapk7.80.0-r0, 7.80.0-r1, 7.80.0-r2, 7.80.0-r3+24 more8.5.0-r0215
curlrpm7.76.1-19.el9, 7.76.1-23.el9_2.1, 7.76.1-23.el9_2.2, 7.76.1-23.el9_2.4+1 more0:7.76.1-23.el9_2.6, 0:7.76.1-26.el9_3.323
OSV records
ALPINE-CVE-2023-46218DEBIAN-CVE-2023-46218RHSA-2024:0452RHSA-2024:1129UBUNTU-CVE-2023-46218DSA-5587-1
Also known as
USN-6535-1, USN-6641-1

Charts affected

904 by stars
ChartLatestAffected imagesRadar Score
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
curl@7.80.0-r1
8.5.0-r0
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
curl@7.80.0-r5
8.5.0-r0

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.5.0-r0

Open the chart page →

5,033
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-46218.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11

Open the chart page →

1,838

Container images carrying it

826 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/ttyd:latestd79c1c5881c0
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm3
1
codercom/code-server:4.11.0-debian1e2cc688008e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
curl@7.87.0-r0
8.5.0-r0
1
cribl/cribl:3.0.2762747cb6796
curl@7.58.0-2ubuntu3.13
7.58.0-2ubuntu3.24+esm3
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
curl@7.47.0-1ubuntu2.19
7.47.0-1ubuntu2.19+esm11
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
danuk/telegram-sender:0.0.1026560388070
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
darkobas/ethexporter:latest62e6464491ba
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
darkobas/tokenexporter:latesta0349a0eedf0
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
daskdev/dask-notebook:1.1.0052630f5ca04
curl@7.58.0-2ubuntu3.5
7.58.0-2ubuntu3.24+esm3
1
datalust/seq:5.0.832-pre9c731bb207a6
curl@7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.19+esm11
1
datappeal/hive-metastore:lateste38c085a3567
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u11
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
curl@7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.15
1
dellcloud/category:distributed02fc234353a9
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
1
dellcloud/pages:1.04d2eb25b9225
curl@7.68.0-1ubuntu2.4
7.68.0-1ubuntu2.21
1
devopstales/trivy-operator:2.575136aa7a26e
curl@7.87.0-r1
8.5.0-r0
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
curl@7.80.0-r3
8.5.0-r0
1
dniel/api-posts:master45a667852f2a
curl@7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.24+esm3
1
dnsforge/xteve:latest4d9a685c8c28
curl@7.87.0-r1
8.5.0-r0
1
dobtc/bitcoin:25.1a870f7cb1105
curl@7.88.1-10+deb12u4
7.88.1-10+deb12u5
1
douz/helpdesk:latest4384103d0219
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u11
1
dremio/dremio-oss:24.1.080ed2e3b7c43
curl@7.81.0-1ubuntu1.10
7.81.0-1ubuntu1.15
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
curl@7.88.1-r0
8.5.0-r0
1
duck1123/astral:latestf4d5b6526c2a
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
1
duck1123/cert-downloader:latest0e29f19fa67c
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.15
1
duck1123/lnd-fileserver:latest9d6fb247b714
curl@7.81.0-1ubuntu1.13
7.81.0-1ubuntu1.15
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
easypi/openrefine:3.7.0d2950a36a576
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u11
1
easysoft/quickon-zentao:18.5592ad5df1f8b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
curl@7.80.0-r2
8.5.0-r0
1
elastic/apm-server:7.17.6c7a1c63257d0
curl@7.68.0-1ubuntu2.12
7.68.0-1ubuntu2.21
1
elastictranscoder/media:627e21dc963ab3858c6b
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.24+esm3
1
elastictranscoder/media-storage:f6d861a026208b8c2359
curl@7.58.0-2ubuntu3.10
7.58.0-2ubuntu3.24+esm3
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm3
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
curl@7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.24+esm3
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u11
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
curl@7.68.0-1ubuntu2.7
7.68.0-1ubuntu2.21
1
emqx/emqx:4.4.41d36535ba9de
curl@7.80.0-r1
8.5.0-r0
1
emqx/emqx:4.4.1971db5ed95db3
curl@8.1.2-r0
8.5.0-r0
1
engrmth/bnkr:2.1.06d8464e6f0e8
curl@7.68.0-1ubuntu2.11
7.68.0-1ubuntu2.21
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
curl@8.4.0-r0
8.5.0-r0
1
eqalpha/keydb:alpine_x86_64_v6.3.4f1d60f12cb3c
curl@8.4.0-r0
8.5.0-r0
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
curl@7.58.0-2ubuntu3.22
7.58.0-2ubuntu3.24+esm3
1
erlangsolutions/wombatoam:4.1.284680c990147a
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u11
1
errbotio/errbot:6.1.900ee4e0953ab
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u11
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
curl@7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.19+esm11
1
ethereumoptimism/l2geth:0.5.315577036dc36d
curl@7.80.0-r5
8.5.0-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.