StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

10,061
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,032
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
adolfintel/speedtest:latest1f828fe83374
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,152
block-buster-helm-appbb-app-helm-chartsVerified publisher7.6.21 of 1See more

block-buster-helm-app bb-app-helm-charts 7.6.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,342
block-buster-helm-appblockbaster-helmapp7.6.01 of 1See more

block-buster-helm-app blockbaster-helmapp 7.6.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

2,507
phpcamptocamp31.0.01 of 1See more

php camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/php:7.3-apacheb9872cd287ef
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,309
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
curl@7.61.1-14.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,389
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,776
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
n22107670/sample-app:0.4.08f3072db7aeb
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,775
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
countly/frontend:25.05.42acbc11499b6
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16

Open the chart page →

7,295
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,423
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
curl@7.61.1-34.el8_10.8
0:7.61.1-34.el8_10.9

Open the chart page →

1,617
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

20,900
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9

Open the chart page →

25,151
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.14 of 12See more

robot-shop cloud-native-toolkit 1.1.1

4 of the 12 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-payment:latest774b52c6180d
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-ratings:latest4899c686c249
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-shipping:latest89753ab48919
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

29,555
default-chartcnieg3.0.81 of 1See more

default-chart cnieg 3.0.8

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23.2ab589a3c466e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

915
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

19,338
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,291
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

5,958
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.11 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

10,091
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

1,797
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-zookeeper:6.1.078c190f4472c
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

58,857
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16

Open the chart page →

11,335
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aristidetm/k8s-hub:3.3.7ccb516cb8474
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

16,604
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

3,547
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,486
symfony-appdefault-ghVerified publisher0.6.51 of 3See more

symfony-app default-gh 0.6.5

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23f5747a42e3ad
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

5,122
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
curl@7.76.1-29.el9_4.1
0:7.76.1-35.el9_7.3

Open the chart page →

3,191
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

29,033
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

12,992
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,237
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

7,459
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,411
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

5,174
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

21,641
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

3,167
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

4,550
tinyproxy-exporterdoubanVerified publisher0.1.21 of 1See more

tinyproxy-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

3,421
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ctron/kubectl:1.25e37d61b5277c
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,362
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,455

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
lmscommunity/logitechmediaserver:8.5.27434f3a6c9cb
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
lnbitsdocker/lnbits-legend:latest26fae6327477
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u16
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
lsstsqre/exposurelog:0.8.079b00fb67a65
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
mailserver/docker-mailserver:11.0.0e0809756dc96
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
maissacrement/pock8snodejs:0.0.16da0db1159da
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
mariadb/maxscale:23.02.256c5e0908148
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
matrixdotorg/synapse:v1.78.0def97fd537d8
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
mautic/mautic:v4-apache94ea4acf4049
curl@7.74.0-1.3+deb11u14
7.74.0-1.3+deb11u16
1
mezmohq/vector:1.17.3ad5794b112af
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
michaelepitech/sample-app:latestaf51d61c19f5
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
mide/minecraft-overviewer:latest4eee0dcb715f
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
minio/kes:v0.22.255f3aef5803e
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
minio/operator:v5.0.9170b154d2c61
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
minio/operator:v4.1.02adc5be088f5
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9
1
mishtinetwork/operator:latestbb3fe67a5f7c
curl@7.74.0-1.3+deb11u14
7.74.0-1.3+deb11u16
1
mnaggar3396/python-app:latest371d8ed84b15
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
mozilla/syncstorage-rs:0.15.893752877dced
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
n22107670/sample-app:0.4.08f3072db7aeb
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
nacos/nacos-server:v3.0.20e951a1d07bb
curl@8.14.1-r0
8.14.1-r2
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
natsio/nats-box:0.18.0abdc9f9f0120
curl@8.14.1-r0
8.14.1-r2
1
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
curl@8.14.1-2
8.14.1-2+deb13u1
1
nginxdemos/hello:plain-text751bf8933179
curl@8.14.1-r1
8.14.1-r2
1
nginxdemos/hello:0.4b28d1e16c676
curl@8.14.1-r1
8.14.1-r2
1
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
curl@8.14.1-r1
8.14.1-r2
1
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
nrrrus/nginx-test:latest5f55cd4ef557
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
ntakashi/gitana:1.4.04171ec641120
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
opencsghq/csgship-agentic:v0.4.02cd29671a03e
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
openhab/openhab:3.2.0d0aa4af452c1
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
otel/opentelemetry-ebpf-kernel-collector:v0.10.269e19991e328
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
owanio1992/devpi:6.16.04ade8e1e4d7e
curl@7.74.0-1.3+deb11u14
7.74.0-1.3+deb11u16
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
pecan/web:1.7.2814d678c5550
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.