StackRadar

CVE-2024-6874

Medium

Advisory

Published 24 Jul 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
193
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 193 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+14 more8.9.0-r0193
OSV records
ALPINE-CVE-2024-6874

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.9.0-r0

Open the chart page →

2,635
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
curl@8.4.0-r0
8.9.0-r0

Open the chart page →

4,060
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.9.0-r0

Open the chart page →

2,030
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.9.0-r0

Open the chart page →

1,611
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.9.0-r0

Open the chart page →

5,033
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.9.0-r0

Open the chart page →

1,589

Container images carrying it

193 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
udhos/forward:1.1.312e120d39fdb
curl@8.1.2-r0
8.9.0-r0
1
udhos/prime:1.0.0e432012dd34a
curl@8.1.2-r0
8.9.0-r0
1
vaultwarden/server:1.27.0-alpine7cd450642c54
curl@7.87.0-r0
8.9.0-r0
1
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.9.0-r0
1
xvilo/php:8.2-composera138e57d3204
curl@7.87.0-r1
8.9.0-r0
1
zurdi15/romm:2.3.12db88fe44c89
curl@8.5.0-r0
8.9.0-r0
1
gcr.io/kubecost1/frontend:prod-1.108.14c6df805bbf2
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/axoflow/axosyslog:4.5.0aa7831e207cd
curl@8.4.0-r0
8.9.0-r0
1
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
curl@8.3.0-r0
8.9.0-r0
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
curl@7.87.0-r1
8.9.0-r0
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/data-fair/metrics:0a8d40779eeae
curl@8.1.2-r0
8.9.0-r0
1
ghcr.io/data-fair/processings:15a9216989707
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/debridmediamanager/zurg-testing:v0.9.3-final5c47ef99443a
curl@8.8.0-r0
8.9.0-r0
1
ghcr.io/devops-ia/kafka-cruise-control-ui:0.4.096c25035cb02
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
curl@7.87.0-r1
8.9.0-r0
1
ghcr.io/gabe565/mnemonic-ninja:latest1fd90a9e4d04
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
curl@8.4.0-r0
8.9.0-r0
1
ghcr.io/k10app/businit:latest94c9a3e799c2
curl@7.86.0-r1
8.9.0-r0
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
curl@8.2.1-r0
8.9.0-r0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
curl@8.2.1-r0
8.9.0-r0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
curl@7.87.0-r2
8.9.0-r0
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/onedr0p/qbittorrent:4.5.20efdd8d3ef39
curl@8.0.1-r2
8.9.0-r0
1
ghcr.io/onedr0p/qbittorrent:4.6.3a4ad890e8c4a
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/pascaliske/traefik-errors:1.1.00cf31753ce57
curl@8.1.2-r0
8.9.0-r0
1
ghcr.io/puckpuck/seashell:1.2ef5e31333821
curl@8.3.0-r0
8.9.0-r0
1
ghcr.io/tasmoadmin/tasmoadmin:v3.3.205aeefbdac2b
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
curl@8.5.0-r0
8.9.0-r0
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
curl@8.7.1-r0
8.9.0-r0
1
ghcr.io/zazuko/blueprint:v0.1.092ac2f97978e
curl@8.5.0-r0
8.9.0-r0
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
curl@8.1.0-r0
8.9.0-r0
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
curl@8.0.1-r0
8.9.0-r0
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
curl@8.5.0-r0
8.9.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
curl@7.87.0-r1
8.9.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
curl@8.5.0-r0
8.9.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
curl@8.1.1-r1
8.9.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
curl@7.88.1-r1
8.9.0-r0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
curl@8.5.0-r0
8.9.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.