StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,787 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,787 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
face-recognitionmoreillonVerified publisher0.2.42 of 3See more

face-recognition moreillon 0.2.4

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
moreillon/face-recognition-fastapi:x86bacb2ddd8394
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

8,556
mqtt-loggermoreillonVerified publisher0.3.13 of 5See more

mqtt-logger moreillon 0.3.1

3 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16

Open the chart page →

10,959
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

25,704
multusmultusVerified publisher0.2.01 of 2See more

multus multus 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

1,852
hello-wordmuraig-hello-word0.2.21 of 1See more

hello-word muraig-hello-word 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.24.0f6daac2445b0
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

532
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

9,149
Practica_4_helmmy-heml-appVerified publisher0.1.02 of 7See more

Practica_4_helm my-heml-app 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
codeurjc/weatherservice:v1.0b9e2f7234349
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

27,721
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

9,542
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
pecan/web:1.7.2814d678c5550
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

14,154
smilencsaVerified publisher1.1.09 of 23See more

smile ncsa 1.1.0

9 of the 23 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/classification_split:0.1.24bfda60829fe
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/classification_train:0.1.207477060bba8
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_list:0.1.051cb17626519
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16

Open the chart page →

109,294
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,982
neuralbank-stackneuralbank-stack0.1.02 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

5,191
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

7,310
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,843
nfl-walletnfl-walletVerified publisher0.1.33 of 4See more

nfl-wallet nfl-wallet 0.1.3

3 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9

Open the chart page →

13,041
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

7,035
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

3,419
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

1,902
liquidsoapnorth141.0.01 of 1See more

liquidsoap north14 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

2,954
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,422
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,875
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

4,547
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,873
lensoci-ai-incubations0.1.143 of 16See more

lens oci-ai-incubations 0.1.14

3 of the 16 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
curl@8.14.1-r0
8.14.1-r2
grafana/grafana:12.1.1a1701c218024
curl@8.14.1-r1
8.14.1-r2
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

17,070
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2

Open the chart page →

1,563
managed-serviceaccountocm-helm-chartsVerified publisher0.10.01 of 1See more

managed-serviceaccount ocm-helm-charts 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/managed-serviceaccount:v0.10.0d6284bd7765a
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,033
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,540
apicurioone-acre-fundVerified publisher2.3.04 of 5See more

apicurio one-acre-fund 2.3.0

4 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

18,667
one-green-coreone-green-coreVerified publisher0.0.71 of 8See more

one-green-core one-green-core 0.0.7

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/telegraf:1.20.428e98eece020
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

9,558
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

18,023
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

41,044
openldapopenldap0.1.11 of 2See more

openldap openldap 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

7,459
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,796
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

2,370
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
andrianrf/backoffice-be:latest6036614803d4
curl@7.76.1-23.el9_2.1
0:7.76.1-23.el9_2.8
andrianrf/iso-server:latest7da47f525c7d
curl@7.76.1-23.el9_2.1
0:7.76.1-23.el9_2.8

Open the chart page →

34,671
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
curl@7.76.1-29.el9_4.1
0:7.76.1-29.el9_4.3
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3

Open the chart page →

18,922
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

13,000
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9

Open the chart page →

16,556
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

4,127
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
curl@7.61.1-18.el8_4.2
0:7.61.1-34.el8_10.9
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9

Open the chart page →

19,455
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,063
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
curl@7.76.1-23.el9_2.2
0:7.76.1-23.el9_2.8

Open the chart page →

8,599
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,738

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
curl@8.14.1-2
8.14.1-2+deb13u1
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
curl@7.76.1-26.el9_3.3
0:7.76.1-35.el9_7.3
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9
1
ghcr.io/k10app/frontend:latest066b5ac6b119
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
ghcr.io/k10app/staticcache:lateste77805689a8e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
ghcr.io/k8s-at-home/theme-park:v1.7.3f8a5ec8f4669
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
1
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
ghcr.io/kiaedev/kiae:latestebd03028ff6a
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
curl@8.14.1-2
8.14.1-2+deb13u1
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
ghcr.io/libretime/libretime-api:latesteae026cc8909
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
ghcr.io/libretime/libretime-legacy:latest35b4531189c2
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
ghcr.io/linuxforhealth/fhir-schematool:5.1.1f62cefee6ef6
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
ghcr.io/monicahq/monica-next:main8be69156acbb
curl@8.14.1-2
8.14.1-2+deb13u1
1
ghcr.io/mroxso/pollstr:latest0b4f97faa3d0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
ghcr.io/porelli/firefox-sync:syncstorage-rs-mysql-0.18.27d244e514216
curl@7.74.0-1.3+deb11u14
7.74.0-1.3+deb11u16
1
ghcr.io/port-labs/port-agent:v0.8.12c92d1e223f5c
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e1
1
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3
1
ghcr.io/remla23-team17/app:1.0.05816dbddf47d
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/remla23-team17/model-service:1.0.0aa59fe2c4f6a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
curl@8.14.1-r0
8.14.1-r2
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
1
public.ecr.aws/groundcovercom/temporalio/admin-tools:1.29.7-20260730-1af8cea3b8538
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e1
1
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.