StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
velero-notificationsvelero-notifications1.1.01 of 1See more

velero-notifications velero-notifications 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,285
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,392
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,262
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,262
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

2,132
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,552
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,138
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
curl@8.14.1-r0
8.14.1-r2
temporalio/server:1.29.1c1e3326b2ce1
curl@8.14.1-r0
8.14.1-r2
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

14,983
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,585
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

2,021
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

3,697

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
confluentinc/cp-zookeeper:7.8.0-3-ubi85ca5f3269814
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
countly/api:25.05.4f4cc7447c4f5
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
1
countly/frontend:25.05.42acbc11499b6
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
1
cr0hn/ja-shortener:v0.1.414482d0bc4a1
curl@8.14.1-r1
8.14.1-r2
1
craftypath/sops-operator:v0.8.0402a0024c732
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9
1
ctron/hawkbit-operator:0.1.48fdea8f76499
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9
1
danuk/k8s-sftp-gcs:latestdd0e6585c44f
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
danuk/telegram-sender:0.0.1026560388070
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
darkobas/ethexporter:latest62e6464491ba
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
darkobas/tokenexporter:latesta0349a0eedf0
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
datappeal/hive-metastore:lateste38c085a3567
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
djjudas21/nova-exporter:0.0.10e9094580885c
curl@8.14.1-r1
8.14.1-r2
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
curl@8.14.1-2
8.14.1-2+deb13u1
1
douz/helpdesk:latest4384103d0219
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
duck1123/astral:latestf4d5b6526c2a
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
easypi/openrefine:3.7.0d2950a36a576
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
easysoft/quickon-zentao:18.5592ad5df1f8b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
emberstack/sftp:5.1.711d81a5df909b
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
1
erenozcan17/react_frontend:v4.56e1b14973f9b
curl@8.14.1-r1
8.14.1-r2
1
erlangsolutions/wombatoam:4.1.284680c990147a
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
errbotio/errbot:6.1.900ee4e0953ab
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
esteban1930/frontend-1:1.8.0f9078279632c
curl@8.14.1-r1
8.14.1-r2
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
curl@8.14.1-2
8.14.1-2+deb13u1
1
fanzynoodle/smeejas:0.0.15f9916c1a287
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
farberg/apache-knox-docker:1.6.14b4a22487394
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
filegator/filegator:latestce163db220d4
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
fiware/mintaka:0.7.092a3c5cf43c0
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
fiware/mintaka:latestefc6793388cc
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
fiware/orion-ld:1.10.03c490a746f65
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
1
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
golenski/db-init:1.0.086ca17cd3063
curl@7.74.0-1.3+deb11u13
7.74.0-1.3+deb11u16
1
gotify/server:2.1.409c79bc1e403
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
gradiant/hdfs:3.2.2e3bf364fe713
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
grafana/grafana:12.2.074144189b384
curl@8.14.1-r1
8.14.1-r2
1
grafana/grafana:12.1.1a1701c218024
curl@8.14.1-r1
8.14.1-r2
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
1
gurolakman/oam:4.0.0ed8fd2062548
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.