StackRadar

CVE-2024-2466

Medium

Advisory

Published 27 Mar 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
88
of 17,781 indexed, latest versions
Container images
85
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 88 of 17,781 indexed charts deploy, on 85 images.

Affected packageAffected versionsFixed inImages
curlapk8.5.0-r08.7.1-r085
OSV records
ALPINE-CVE-2024-2466

Charts affected

88 by stars
ChartLatestAffected imagesRadar Score
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

5,332
qbittorrentnoxleonardo0918000.1.01 of 1See more

qbittorrentnox leonardo091800 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,118
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
curl@8.5.0-r0
8.7.1-r0
sky5367/locust-plugins-timescale:latestd3150f201471
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

7,510
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,225
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,225
magistralamagistrala-devopsVerified publisher0.16.22 of 42See more

magistrala magistrala-devops 0.16.2

2 of the 42 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.31cc420186664
curl@8.5.0-r0
8.7.1-r0
supermq/vernemq:latest944a0be3563e
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

24,400
prometheus-exportermakaira1.2.21 of 2See more

prometheus-exporter makaira 1.2.2

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
library/nginx:1.24-alpine77e5d4a6ad90
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

652
matrix-sliding-syncmatrix-sliding-sync0.2.31 of 1See more

matrix-sliding-sync matrix-sliding-sync 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,592
cognativemyaVerified publisher0.2403.31 of 3See more

cognative mya 0.2403.3

1 of the 3 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

7,309
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,430
nginx-playgroundmysql2s3bk0.1.01 of 1See more

nginx-playground mysql2s3bk 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
library/nginx:1.24-alpine77e5d4a6ad90
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

652
nginx-custom-selinuxnginx-custom1.0.01 of 1See more

nginx-custom-selinux nginx-custom 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
library/nginx:1.25-alpine516475cc129d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

686
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,966
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

9,724
lokiot-container-kit1.0.11 of 5See more

loki ot-container-kit 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,831
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

5,137
k8s-node-image-1-21pnnl-miscscripts0.2.1491 of 2See more

k8s-node-image-1-21 pnnl-miscscripts 0.2.149

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
k8s-node-image-1-22pnnl-miscscripts0.2.1171 of 2See more

k8s-node-image-1-22 pnnl-miscscripts 0.2.117

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
k8s-node-image-1-23pnnl-miscscripts0.2.1231 of 2See more

k8s-node-image-1-23 pnnl-miscscripts 0.2.123

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
k8s-node-image-1-24pnnl-miscscripts0.2.1281 of 2See more

k8s-node-image-1-24 pnnl-miscscripts 0.2.128

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,038
chainrss30.1.282 of 8See more

chain rss3 0.1.28

2 of the 8 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

8,528
proxydrss30.1.01 of 1See more

proxyd rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,110
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,610
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.7.1-r0
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,881
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,337
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,825
mimirskyloud-helm-chartsVerified publisher5.5.11 of 5See more

mimir skyloud-helm-charts 5.5.1

1 of the 5 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

10,651
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,416
ingress-nginx-external-lbsuminhong1.0.01 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,094
snmp-managersvtech-public-helm-charts1.1.01 of 1See more

snmp-manager svtech-public-helm-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

761
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,336
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,806
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,477
demo-frontendv2flyVerified publisher0.0.31 of 1See more

demo-frontend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

753
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,611
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,589

Container images carrying it

85 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
curl@8.5.0-r0
8.7.1-r0
1
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
curl@8.5.0-r0
8.7.1-r0
1
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
curl@8.5.0-r0
8.7.1-r0
1
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
curl@8.5.0-r0
8.7.1-r0
1
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.7.1-r0
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.7.1-r0
1
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.7.1-r0
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
curl@8.5.0-r0
8.7.1-r0
1
sky5367/locust-plugins-timescale:latestd3150f201471
curl@8.5.0-r0
8.7.1-r0
1
supermq/vernemq:latest944a0be3563e
curl@8.5.0-r0
8.7.1-r0
1
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.7.1-r0
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.7.1-r0
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
curl@8.5.0-r0
8.7.1-r0
1
temporalio/server:1.25.08a5798191dea
curl@8.5.0-r0
8.7.1-r0
1
temporalio/ui:2.30.25c2a3645d09c
curl@8.5.0-r0
8.7.1-r0
1
temporalio/ui:2.33.05c586a3c8ec5
curl@8.5.0-r0
8.7.1-r0
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
curl@8.5.0-r0
8.7.1-r0
1
zurdi15/romm:2.3.12db88fe44c89
curl@8.5.0-r0
8.7.1-r0
1
gcr.io/kubecost1/frontend:prod-1.108.14c6df805bbf2
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/data-fair/processings:15a9216989707
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/devops-ia/kafka-cruise-control-ui:0.4.096c25035cb02
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/gabe565/mnemonic-ninja:latest1fd90a9e4d04
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
curl@8.5.0-r0
8.7.1-r0
1
ghcr.io/zazuko/blueprint:v0.1.092ac2f97978e
curl@8.5.0-r0
8.7.1-r0
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.7.1-r0
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.7.1-r0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
curl@8.5.0-r0
8.7.1-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.