StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

10,061
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,032
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
adolfintel/speedtest:latest1f828fe83374
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,152
block-buster-helm-appbb-app-helm-chartsVerified publisher7.6.21 of 1See more

block-buster-helm-app bb-app-helm-charts 7.6.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,342
block-buster-helm-appblockbaster-helmapp7.6.01 of 1See more

block-buster-helm-app blockbaster-helmapp 7.6.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

2,507
phpcamptocamp31.0.01 of 1See more

php camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/php:7.3-apacheb9872cd287ef
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,309
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
curl@7.61.1-14.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,389
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,776
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
n22107670/sample-app:0.4.08f3072db7aeb
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,775
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
countly/frontend:25.05.42acbc11499b6
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16

Open the chart page →

7,295
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,423
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
curl@7.61.1-34.el8_10.8
0:7.61.1-34.el8_10.9

Open the chart page →

1,617
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

20,900
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9

Open the chart page →

25,151
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.14 of 12See more

robot-shop cloud-native-toolkit 1.1.1

4 of the 12 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-payment:latest774b52c6180d
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-ratings:latest4899c686c249
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-shipping:latest89753ab48919
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

29,555
default-chartcnieg3.0.81 of 1See more

default-chart cnieg 3.0.8

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23.2ab589a3c466e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

915
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

19,338
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,291
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

5,958
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.11 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

10,091
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

1,797
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-zookeeper:6.1.078c190f4472c
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

58,857
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16

Open the chart page →

11,335
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aristidetm/k8s-hub:3.3.7ccb516cb8474
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

16,604
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

3,547
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,486
symfony-appdefault-ghVerified publisher0.6.51 of 3See more

symfony-app default-gh 0.6.5

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23f5747a42e3ad
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

5,122
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
curl@7.76.1-29.el9_4.1
0:7.76.1-35.el9_7.3

Open the chart page →

3,191
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

29,033
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

12,992
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,237
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

7,459
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,411
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

5,174
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

21,641
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

3,167
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

4,550
tinyproxy-exporterdoubanVerified publisher0.1.21 of 1See more

tinyproxy-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

3,421
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ctron/kubectl:1.25e37d61b5277c
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,362
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,455

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
atomix/atomix:3.1.127738ff4f5c63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
azhar008/flaskapplication:latesta1e827b0adea
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
beopenit/door-helm:v3.0.1b4d9f9bee224
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
curl@8.14.1-2
8.14.1-2+deb13u1
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
curl@8.14.1-r0
8.14.1-r2
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
bitnamilegacy/kubectl:1.22.13d0e426ccff33
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bsgrigorov/helm-operator:latest45ab095f09c8
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
buntha/mlflow:2.1.1154542cc3083
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
curl@8.14.1-r1
8.14.1-r2
1
chubaofs/cfs-client:3.2.015ff74209ce7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
chubaofs/cfs-server:3.2.0205030e045f2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
cleveritcz/opencve:1.5.0c75c1636e0b7
curl@7.76.1-26.el9_3.3
0:7.76.1-35.el9_7.3
1
cm2network/csgo:sourcemod93df54a2e4fb
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
1
cockroachdb/cockroach-operator:v2.1.0983312754620
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9
1
codercom/code-server:4.11.0-debian1e2cc688008e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
coderenvs/coder-service:1.44.61deffc4670e6
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.9
1
coderenvs/timescale:1.44.676fd37fe6830
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.9
1
codetogether/codetogether:latest4348c8a38752
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.5.1dc9b972db002
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.