CVE-2024-0853
MediumAdvisory
Published 3 Feb 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.011
- 64th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 201
- of 17,787 indexed, latest versions
- Container images
- 189
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
curl-8.6.0-1.1 on GA media
Carried by container images the latest versions of 201 of 17,787 indexed charts deploy, on 189 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| curlapk | 7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+12 more | 8.6.0-r0 | 187 |
| curlrpm | 7.60.0-lp151.5.6.1 | 8.6.0-1.1 | 2 |
- OSV records
- ALPINE-CVE-2024-0853openSUSE-SU-2024:13637-1
Charts affected
201 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,588 |
Container images carrying it
189 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ddosify/ | bf454ab99d89 | curl | 8.6.0-r0 | 1 |
| defactops/ | 825cdf9ba706 | curl | 8.6.0-r0 | 1 |
| devopstales/ | 75136aa7a26e | curl | 8.6.0-r0 | 1 |
| dgtlmoon/ | f166a963b550 | curl | 8.6.0-r0 | 1 |
| dnsforge/ | 4d9a685c8c28 | curl | 8.6.0-r0 | 1 |
| dragonflyoss/ | c3ef7f10698d | curl | 8.6.0-r0 | 1 |
| dragonflyoss/ | 523785c77787 | curl | 8.6.0-r0 | 1 |
| dtzar/ | a1041bb0f1d1 | curl | 8.6.0-r0 | 1 |
| epamedp/ | 28ef56bc0ca3 | curl | 8.6.0-r0 | 1 |
| eqalpha/ | f1d60f12cb3c | curl | 8.6.0-r0 | 1 |
| factly/ | 9db4bee30e63 | curl | 8.6.0-r0 | 1 |
| fedodo/ | c69413c4d690 | curl | 8.6.0-r0 | 1 |
| fedodo/ | b2b540081c21 | curl | 8.6.0-r0 | 1 |
| feiyu563/ | 224cfa68cbd9 | curl | 8.6.0-r0 | 1 |
| felipecs8/ | d5f4f17cb066 | curl | 8.6.0-r0 | 1 |
| firefart/ | 1028236b42a0 | curl | 8.6.0-r0 | 1 |
| folioci/ | 3028f333778f | curl | 8.6.0-r0 | 1 |
| gitea/ | ac73e0da341f | curl | 8.6.0-r0 | 1 |
| glenndehaan/ | a5b3f1dd865d | curl | 8.6.0-r0 | 1 |
| grafana/ | 0679e877ba20 | curl | 8.6.0-r0 | 1 |
| grafana/ | 1b9ca4bbc4a2 | curl | 8.6.0-r0 | 1 |
| grafana/ | 39c849cebccc | curl | 8.6.0-r0 | 1 |
| grafana/ | 6b5b37eb35bb | curl | 8.6.0-r0 | 1 |
| grafana/ | 8640e5038e83 | curl | 8.6.0-r0 | 1 |
| grafana/ | f9811e4e687f | curl | 8.6.0-r0 | 1 |
| hansehe/ | 58e09540afbc | curl | 8.6.0-r0 | 1 |
| haproxytech/ | c5f8a41ef0d4 | curl | 8.6.0-r0 | 1 |
| hashicorp/ | 712fe02d2f84 | curl | 8.6.0-r0 | 1 |
| hashicorp/ | ddff34041c5c | curl | 8.6.0-r0 | 1 |
| hashicorp/ | 4dcb45513699 | curl | 8.6.0-r0 | 1 |
| hashicorp/ | 97d521a27498 | curl | 8.6.0-r0 | 1 |
| hazelcast/ | 8fe26efde8e1 | curl | 8.6.0-r0 | 1 |
| hngtech11/ | f0112dc12cfb | curl | 8.6.0-r0 | 1 |
| homeassistant/ | 021e2afc6e57 | curl | 8.6.0-r0 | 1 |
| homeassistant/ | 8d000332b09b | curl | 8.6.0-r0 | 1 |
| i4trust/ | 9f3719176893 | curl | 8.6.0-r0 | 1 |
| intelloop/ | 2409c2a00ab6 | curl | 8.6.0-r0 | 1 |
| invoiceninja/ | 1437916dee01 | curl | 8.6.0-r0 | 1 |
| iomesh/ | 063b18afb6a1 | curl | 8.6.0-r0 | 1 |
| iomesh/ | 4206d42b92f1 | curl | 8.6.0-r0 | 1 |
| jupyterhub/ | 7adeeed34a36 | curl | 8.6.0-r0 | 1 |
| kfirfer/ | c257c1e0e8b9 | curl | 8.6.0-r0 | 1 |
| kfirfer/ | c05d9fc7ae77 | curl | 8.6.0-r0 | 1 |
| kfirfer/ | d23d173f333f | curl | 8.6.0-r0 | 1 |
| kubegems/ | c3b4be9a54f5 | curl | 8.6.0-r0 | 1 |
| kubeshop/ | 48958b4126a4 | curl | 8.6.0-r0 | 1 |
| kubestar/ | 656606941255 | curl | 8.6.0-r0 | 1 |
| kubevirtmanager/ | df3ea27d4a9e | curl | 8.6.0-r0 | 1 |
| kvalitetsit/ | fd5c4f60ef80 | curl | 8.6.0-r0 | 1 |
| kyso/ | 82299a9e5a86 | curl | 8.6.0-r0 | 1 |