StackRadar

CVE-2024-6874

Medium

Advisory

Published 24 Jul 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
193
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 193 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+14 more8.9.0-r0193
OSV records
ALPINE-CVE-2024-6874

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.9.0-r0

Open the chart page →

2,635
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
curl@8.4.0-r0
8.9.0-r0

Open the chart page →

4,060
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.9.0-r0

Open the chart page →

2,030
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.9.0-r0

Open the chart page →

1,611
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.9.0-r0

Open the chart page →

5,033
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.9.0-r0

Open the chart page →

1,589

Container images carrying it

193 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/docker:26.1-dinddd43b430341a
curl@8.8.0-r0
8.9.0-r0
1
library/influxdb:2.7.4-alpinea10d46445d68
curl@8.4.0-r0
8.9.0-r0
1
library/nginx:1.25.4-alpine31bad00311cb
curl@8.5.0-r0
8.9.0-r0
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
curl@8.2.1-r0
8.9.0-r0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
curl@7.88.1-r1
8.9.0-r0
1
linuxserver/yq:3.2.26f5b9586a93e
curl@8.2.1-r0
8.9.0-r0
1
metabase/metabase:v0.46.09ebdc664a6b2
curl@7.88.1-r1
8.9.0-r0
1
natsio/nats-box:0.14.31cc420186664
curl@8.5.0-r0
8.9.0-r0
1
natsio/nats-box:0.13.559cf2e949181
curl@7.88.1-r0
8.9.0-r0
1
natsio/nats-box:0.14.2e808e0644ce1
curl@8.5.0-r0
8.9.0-r0
1
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
curl@8.5.0-r0
8.9.0-r0
1
nginxinc/nginx-unprivileged8f14986c54fa
curl@8.5.0-r0
8.9.0-r0
1
nodered/node-red:3.0.2-18e2632a7a35dd
curl@8.5.0-r0
8.9.0-r0
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
curl@8.5.0-r0
8.9.0-r0
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
curl@8.1.2-r0
8.9.0-r0
1
phntom/chartmuseum:v0.16.053883b65d9b7
curl@8.2.0-r1
8.9.0-r0
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
curl@7.86.0-r1
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
curl@8.5.0-r0
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
curl@8.5.0-r0
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
curl@8.5.0-r0
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
curl@8.5.0-r0
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.23.17-nginx-3479ada675515f
curl@8.2.1-r0
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.22.17-nginx-34b85e437ae261
curl@8.2.1-r0
8.9.0-r0
1
pnnlmiscscripts/k8s-node-image9:1.21.14-nginx-33fa8f5906d36a
curl@8.2.1-r0
8.9.0-r0
1
postgis/postgis:15-3.3-alpine4738bee21eb6
curl@8.2.1-r0
8.9.0-r0
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
curl@7.88.1-r1
8.9.0-r0
1
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
curl@8.5.0-r0
8.9.0-r0
1
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
curl@8.5.0-r0
8.9.0-r0
1
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
curl@8.5.0-r0
8.9.0-r0
1
sealio/hermitcrab:v0.1.4a326a2f03660
curl@8.5.0-r0
8.9.0-r0
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
curl@8.5.0-r0
8.9.0-r0
1
semaphoreui/semaphore:v2.9.645b50bc11833f
curl@8.5.0-r0
8.9.0-r0
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
curl@8.5.0-r0
8.9.0-r0
1
sky5367/locust-plugins-timescale:latestd3150f201471
curl@8.5.0-r0
8.9.0-r0
1
supermq/vernemq:latest944a0be3563e
curl@8.5.0-r0
8.9.0-r0
1
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
curl@8.5.0-r0
8.9.0-r0
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
curl@8.5.0-r0
8.9.0-r0
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
curl@8.2.1-r0
8.9.0-r0
1
temporalio/admin-tools:1.22.4258958fe2ff2
curl@8.4.0-r0
8.9.0-r0
1
temporalio/admin-tools:1.22.0836af062af30
curl@8.2.0-r1
8.9.0-r0
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
curl@8.5.0-r0
8.9.0-r0
1
temporalio/server:1.25.08a5798191dea
curl@8.5.0-r0
8.9.0-r0
1
temporalio/server:1.22.0ddeebf8bad8f
curl@8.2.0-r1
8.9.0-r0
1
temporalio/ui:2.30.25c2a3645d09c
curl@8.5.0-r0
8.9.0-r0
1
temporalio/ui:2.33.05c586a3c8ec5
curl@8.5.0-r0
8.9.0-r0
1
thecloudspark/app-result:1.09a5302cb8312
curl@8.7.1-r0
8.9.0-r0
1
thecloudspark/app-vote:1.0c7da7417a86a
curl@8.7.1-r0
8.9.0-r0
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
curl@8.3.0-r0
8.9.0-r0
1
thirtythreeforty/neolink:latestf564c4f538de
curl@8.0.1-r2
8.9.0-r0
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
curl@8.5.0-r0
8.9.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.