StackRadar

CVE-2024-6874

Medium

Advisory

Published 24 Jul 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
206
of 17,781 indexed, latest versions
Container images
193
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 206 of 17,781 indexed charts deploy, on 193 images.

Affected packageAffected versionsFixed inImages
curlapk7.86.0-r1, 7.87.0-r0, 7.87.0-r1, 7.87.0-r2+14 more8.9.0-r0193
OSV records
ALPINE-CVE-2024-6874

Charts affected

206 by stars
ChartLatestAffected imagesRadar Score
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
curl@8.4.0-r0
8.9.0-r0

Open the chart page →

2,635
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
curl@8.4.0-r0
8.9.0-r0

Open the chart page →

4,060
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.9.0-r0

Open the chart page →

2,030
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
curl@8.5.0-r0
8.9.0-r0

Open the chart page →

1,611
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
curl@8.1.2-r0
8.9.0-r0

Open the chart page →

5,033
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-6874.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
curl@8.5.0-r0
8.9.0-r0

Open the chart page →

1,589

Container images carrying it

193 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
natsio/nats-box:0.14.1a67913df95f1
curl@8.4.0-r0
8.9.0-r0
5
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
curl@8.5.0-r0
8.9.0-r0
5
grafana/grafana:11.0.00dc5a246ab16
curl@8.5.0-r0
8.9.0-r0
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
curl@8.5.0-r0
8.9.0-r0
3
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
curl@8.5.0-r0
8.9.0-r0
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
curl@7.88.1-r1
8.9.0-r0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
curl@8.5.0-r0
8.9.0-r0
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
curl@8.5.0-r0
8.9.0-r0
3
quay.io/jupyterhub/configurable-http-proxy:4.6.1fd916f75415f
curl@8.4.0-r0
8.9.0-r0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
curl@8.1.2-r0
8.9.0-r0
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
curl@8.1.1-r1
8.9.0-r0
2
alpine/curl:8.7.1f0c1b7ca12f6
curl@8.7.1-r0
8.9.0-r0
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
curl@8.2.1-r0
8.9.0-r0
2
cs3org/wopiserver:v9.4.202a9e78757b4
curl@7.88.1-r0
8.9.0-r0
2
daniacobext/airports-frontend:latest9eae4d39fc33
curl@8.1.2-r0
8.9.0-r0
2
dtzar/helm-kubectl:3.14.455429449408e
curl@8.5.0-r0
8.9.0-r0
2
ethersphere/bee-localchain:latest0558799ca992
curl@8.5.0-r0
8.9.0-r0
2
grafana/grafana:11.1.0079600c9517b
curl@8.5.0-r0
8.9.0-r0
2
krtk6160/galoy-nostrcc82a694f818
curl@7.87.0-r2
8.9.0-r0
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
curl@7.86.0-r1
8.9.0-r0
2
library/influxdb:2.6.1-alpine44a366dd7724
curl@7.88.1-r1
8.9.0-r0
2
library/nginx:1.24-alpine77e5d4a6ad90
curl@8.5.0-r0
8.9.0-r0
2
metabase/metabase:v0.45.21fb334ce4820
curl@7.87.0-r1
8.9.0-r0
2
organizr/organizr:latest1ce319d73cdf
curl@8.4.0-r0
8.9.0-r0
2
taigaio/taiga-front:latest570c8792ce80
curl@7.88.1-r1
8.9.0-r0
2
temporalio/server:1.22.4c0a44c26397b
curl@8.4.0-r0
8.9.0-r0
2
temporalio/ui:2.16.2af9c9349708f
curl@8.1.2-r0
8.9.0-r0
2
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
curl@8.5.0-r0
8.9.0-r0
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
curl@7.87.0-r2
8.9.0-r0
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
curl@8.4.0-r0
8.9.0-r0
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
curl@8.5.0-r0
8.9.0-r0
2
abdullahkhabir/radio:latest56526d0cc929
curl@8.3.0-r0
8.9.0-r0
1
alpine/curl:8.5.0513c4f0d7123
curl@8.5.0-r0
8.9.0-r0
1
alpine/k8s:1.27.321b24e6bf801
curl@8.1.2-r0
8.9.0-r0
1
alpine/k8s:1.30.0bd01dae02676
curl@8.5.0-r0
8.9.0-r0
1
alpine/k8s:1.30.2cd560fce90f7
curl@8.8.0-r0
8.9.0-r0
1
alpine/k8s:1.28.2fc059f056ad0
curl@8.3.0-r0
8.9.0-r0
1
andrcuns/smocker:0.18.5b4a8eb20581a
curl@8.4.0-r0
8.9.0-r0
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
curl@8.5.0-r0
8.9.0-r0
1
aquasec/postee:2.12.0-amd640795cba777e7
curl@8.1.2-r0
8.9.0-r0
1
aquasec/trivy:0.43.1944a04445179
curl@8.1.2-r0
8.9.0-r0
1
casbin/casdoor:v1.224.066f836ef778b
curl@7.87.0-r1
8.9.0-r0
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
curl@8.1.2-r0
8.9.0-r0
1
codecov/self-hosted-api:24.4.10475cb1c3136
curl@8.5.0-r0
8.9.0-r0
1
codecov/self-hosted-frontend:24.4.1534bc4778073
curl@8.5.0-r0
8.9.0-r0
1
codecov/self-hosted-worker:24.4.1837f546b479b
curl@8.5.0-r0
8.9.0-r0
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
curl@7.87.0-r0
8.9.0-r0
1
daledavies/jump:v1.4.10a0c8ad93902
curl@8.5.0-r0
8.9.0-r0
1
datawire/aes:3.11.195ec30b3c732
curl@8.5.0-r0
8.9.0-r0
1
ddosify/selfhosted_frontend:2.7.456dbd7cf0776
curl@8.5.0-r0
8.9.0-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.