StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
face-recognitionmoreillonVerified publisher0.2.42 of 3See more

face-recognition moreillon 0.2.4

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
moreillon/face-recognition-fastapi:x86bacb2ddd8394
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

8,556
mqtt-loggermoreillonVerified publisher0.3.13 of 5See more

mqtt-logger moreillon 0.3.1

3 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16

Open the chart page →

10,959
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

25,704
multusmultusVerified publisher0.2.01 of 2See more

multus multus 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

1,852
hello-wordmuraig-hello-word0.2.21 of 1See more

hello-word muraig-hello-word 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.24.0f6daac2445b0
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

532
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

9,149
Practica_4_helmmy-heml-appVerified publisher0.1.02 of 7See more

Practica_4_helm my-heml-app 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
codeurjc/weatherservice:v1.0b9e2f7234349
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

27,721
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

9,542
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
pecan/web:1.7.2814d678c5550
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

14,154
smilencsaVerified publisher1.1.09 of 23See more

smile ncsa 1.1.0

9 of the 23 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/classification_split:0.1.24bfda60829fe
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/classification_train:0.1.207477060bba8
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_list:0.1.051cb17626519
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16

Open the chart page →

109,294
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,982
neuralbank-stackneuralbank-stack0.1.02 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

5,191
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

7,310
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,843
nfl-walletnfl-walletVerified publisher0.1.33 of 4See more

nfl-wallet nfl-wallet 0.1.3

3 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9

Open the chart page →

13,041
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

7,035
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

3,419
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

1,902
liquidsoapnorth141.0.01 of 1See more

liquidsoap north14 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

2,954
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,422
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,875
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

4,547
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,873
lensoci-ai-incubations0.1.143 of 16See more

lens oci-ai-incubations 0.1.14

3 of the 16 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
curl@8.14.1-r0
8.14.1-r2
grafana/grafana:12.1.1a1701c218024
curl@8.14.1-r1
8.14.1-r2
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

17,070
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2

Open the chart page →

1,563
managed-serviceaccountocm-helm-chartsVerified publisher0.10.01 of 1See more

managed-serviceaccount ocm-helm-charts 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/managed-serviceaccount:v0.10.0d6284bd7765a
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,033
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,540
apicurioone-acre-fundVerified publisher2.3.04 of 5See more

apicurio one-acre-fund 2.3.0

4 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

18,667
one-green-coreone-green-coreVerified publisher0.0.71 of 8See more

one-green-core one-green-core 0.0.7

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/telegraf:1.20.428e98eece020
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

9,558
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

18,023
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

41,044
openldapopenldap0.1.11 of 2See more

openldap openldap 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

7,459
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,796
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

2,370
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
andrianrf/backoffice-be:latest6036614803d4
curl@7.76.1-23.el9_2.1
0:7.76.1-23.el9_2.8
andrianrf/iso-server:latest7da47f525c7d
curl@7.76.1-23.el9_2.1
0:7.76.1-23.el9_2.8

Open the chart page →

34,671
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
curl@7.76.1-29.el9_4.1
0:7.76.1-29.el9_4.3
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3

Open the chart page →

18,922
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

13,000
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9

Open the chart page →

16,556
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

4,127
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
curl@7.61.1-18.el8_4.2
0:7.61.1-34.el8_10.9
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9

Open the chart page →

19,455
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,063
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
curl@7.76.1-23.el9_2.2
0:7.76.1-23.el9_2.8

Open the chart page →

8,599
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,738

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
atomix/atomix:3.1.127738ff4f5c63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
azhar008/flaskapplication:latesta1e827b0adea
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
beopenit/door-helm:v3.0.1b4d9f9bee224
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
curl@8.14.1-2
8.14.1-2+deb13u1
1
beyzkaya/blog-frontend:v1.0.0bf412d75c510
curl@8.14.1-r0
8.14.1-r2
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
bitnamilegacy/kubectl:1.22.13d0e426ccff33
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
bsgrigorov/helm-operator:latest45ab095f09c8
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
buntha/mlflow:2.1.1154542cc3083
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
curl@8.14.1-r1
8.14.1-r2
1
chubaofs/cfs-client:3.2.015ff74209ce7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
chubaofs/cfs-server:3.2.0205030e045f2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
cleveritcz/opencve:1.5.0c75c1636e0b7
curl@7.76.1-26.el9_3.3
0:7.76.1-35.el9_7.3
1
cm2network/csgo:sourcemod93df54a2e4fb
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9
1
cockroachdb/cockroachdb-operator-v2:v1.0.04335d8bcbd3d
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
1
cockroachdb/cockroach-operator:v2.1.0983312754620
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9
1
codercom/code-server:4.11.0-debian1e2cc688008e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
coderenvs/coder-service:1.44.61deffc4670e6
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.9
1
coderenvs/timescale:1.44.676fd37fe6830
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.9
1
codetogether/codetogether:latest4348c8a38752
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.6.683dbca3efd2a
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.8.0-3-ubi8adc392d28a1e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka:7.5.1dc9b972db002
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.