StackRadar

CVE-2024-2466

Medium

Advisory

Published 27 Mar 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
88
of 17,781 indexed, latest versions
Container images
85
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 88 of 17,781 indexed charts deploy, on 85 images.

Affected packageAffected versionsFixed inImages
curlapk8.5.0-r08.7.1-r085
OSV records
ALPINE-CVE-2024-2466

Charts affected

88 by stars
ChartLatestAffected imagesRadar Score
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

5,332
qbittorrentnoxleonardo0918000.1.01 of 1See more

qbittorrentnox leonardo091800 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,118
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
curl@8.5.0-r0
8.7.1-r0
sky5367/locust-plugins-timescale:latestd3150f201471
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

7,510
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,225
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,225
magistralamagistrala-devopsVerified publisher0.16.22 of 42See more

magistrala magistrala-devops 0.16.2

2 of the 42 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.31cc420186664
curl@8.5.0-r0
8.7.1-r0
supermq/vernemq:latest944a0be3563e
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

24,400
prometheus-exportermakaira1.2.21 of 2See more

prometheus-exporter makaira 1.2.2

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
library/nginx:1.24-alpine77e5d4a6ad90
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

652
matrix-sliding-syncmatrix-sliding-sync0.2.31 of 1See more

matrix-sliding-sync matrix-sliding-sync 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,592
cognativemyaVerified publisher0.2403.31 of 3See more

cognative mya 0.2403.3

1 of the 3 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

7,309
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,430
nginx-playgroundmysql2s3bk0.1.01 of 1See more

nginx-playground mysql2s3bk 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
library/nginx:1.24-alpine77e5d4a6ad90
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

652
nginx-custom-selinuxnginx-custom1.0.01 of 1See more

nginx-custom-selinux nginx-custom 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
library/nginx:1.25-alpine516475cc129d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

686
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,966
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

9,724
lokiot-container-kit1.0.11 of 5See more

loki ot-container-kit 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,831
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

5,137
k8s-node-image-1-21pnnl-miscscripts0.2.1491 of 2See more

k8s-node-image-1-21 pnnl-miscscripts 0.2.149

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
k8s-node-image-1-22pnnl-miscscripts0.2.1171 of 2See more

k8s-node-image-1-22 pnnl-miscscripts 0.2.117

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
k8s-node-image-1-23pnnl-miscscripts0.2.1231 of 2See more

k8s-node-image-1-23 pnnl-miscscripts 0.2.123

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
k8s-node-image-1-24pnnl-miscscripts0.2.1281 of 2See more

k8s-node-image-1-24 pnnl-miscscripts 0.2.128

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,403
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,038
chainrss30.1.282 of 8See more

chain rss3 0.1.28

2 of the 8 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

8,528
proxydrss30.1.01 of 1See more

proxyd rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,110
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,610
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.7.1-r0
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

4,881
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

3,337
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,825
mimirskyloud-helm-chartsVerified publisher5.5.11 of 5See more

mimir skyloud-helm-charts 5.5.1

1 of the 5 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

10,651
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,416
ingress-nginx-external-lbsuminhong1.0.01 of 2See more

ingress-nginx-external-lb suminhong 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,094
snmp-managersvtech-public-helm-charts1.1.01 of 1See more

snmp-manager svtech-public-helm-charts 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

761
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,336
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,806
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

2,477
demo-frontendv2flyVerified publisher0.0.31 of 1See more

demo-frontend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

753
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,611
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-2466.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.7.1-r0

Open the chart page →

1,589

Container images carrying it

85 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.7.1-r0
5
grafana/grafana:11.0.00dc5a246ab16
curl@8.5.0-r0
8.7.1-r0
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
curl@8.5.0-r0
8.7.1-r0
3
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
curl@8.5.0-r0
8.7.1-r0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
curl@8.5.0-r0
8.7.1-r0
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.7.1-r0
3
dtzar/helm-kubectl:3.14.455429449408e
curl@8.5.0-r0
8.7.1-r0
2
ethersphere/bee-localchain:latest0558799ca992
curl@8.5.0-r0
8.7.1-r0
2
grafana/grafana:11.1.0079600c9517b
curl@8.5.0-r0
8.7.1-r0
2
library/nginx:1.24-alpine77e5d4a6ad90
curl@8.5.0-r0
8.7.1-r0
2
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
curl@8.5.0-r0
8.7.1-r0
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
curl@8.5.0-r0
8.7.1-r0
2
alpine/curl:8.5.0513c4f0d7123
curl@8.5.0-r0
8.7.1-r0
1
alpine/k8s:1.30.0bd01dae02676
curl@8.5.0-r0
8.7.1-r0
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.7.1-r0
1
codecov/self-hosted-api:24.4.10475cb1c3136
curl@8.5.0-r0
8.7.1-r0
1
codecov/self-hosted-frontend:24.4.1534bc4778073
curl@8.5.0-r0
8.7.1-r0
1
codecov/self-hosted-worker:24.4.1837f546b479b
curl@8.5.0-r0
8.7.1-r0
1
daledavies/jump:v1.4.10a0c8ad93902
curl@8.5.0-r0
8.7.1-r0
1
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.7.1-r0
1
ddosify/selfhosted_frontend:2.7.456dbd7cf0776
curl@8.5.0-r0
8.7.1-r0
1
ddosify/selfhosted_frontend:4.1.5bf454ab99d89
curl@8.5.0-r0
8.7.1-r0
1
defactops/defactops-ui:1.0.16825cdf9ba706
curl@8.5.0-r0
8.7.1-r0
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.7.1-r0
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
curl@8.5.0-r0
8.7.1-r0
1
dragonflyoss/scheduler:v2.1.49523785c77787
curl@8.5.0-r0
8.7.1-r0
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.7.1-r0
1
gitea/gitea:1.21.6ac73e0da341f
curl@8.5.0-r0
8.7.1-r0
1
grafana/grafana:10.2.36b5b37eb35bb
curl@8.5.0-r0
8.7.1-r0
1
grafana/grafana:10.3.38640e5038e83
curl@8.5.0-r0
8.7.1-r0
1
grafana/grafana:10.4.0f9811e4e687f
curl@8.5.0-r0
8.7.1-r0
1
hansehe/graphql-gateway:1.0.458e09540afbc
curl@8.5.0-r0
8.7.1-r0
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
curl@8.5.0-r0
8.7.1-r0
1
hngtech11/hello-world:v1f0112dc12cfb
curl@8.5.0-r0
8.7.1-r0
1
intelloop/atlas-cmms-frontend:v1.5.12409c2a00ab6
curl@8.5.0-r0
8.7.1-r0
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
curl@8.5.0-r0
8.7.1-r0
1
kfirfer/mysql-client:0.0.4d23d173f333f
curl@8.5.0-r0
8.7.1-r0
1
kubeshop/testkube-dashboard:1.16.748958b4126a4
curl@8.5.0-r0
8.7.1-r0
1
kubestar/event-exporter:latest656606941255
curl@8.5.0-r0
8.7.1-r0
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
curl@8.5.0-r0
8.7.1-r0
1
library/nginx:1.25.4-alpine31bad00311cb
curl@8.5.0-r0
8.7.1-r0
1
natsio/nats-box:0.14.31cc420186664
curl@8.5.0-r0
8.7.1-r0
1
natsio/nats-box:0.14.2e808e0644ce1
curl@8.5.0-r0
8.7.1-r0
1
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.7.1-r0
1
nginxinc/nginx-unprivileged8f14986c54fa
curl@8.5.0-r0
8.7.1-r0
1
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.7.1-r0
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
curl@8.5.0-r0
8.7.1-r0
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
curl@8.5.0-r0
8.7.1-r0
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
curl@8.5.0-r0
8.7.1-r0
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
curl@8.5.0-r0
8.7.1-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.