StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
face-recognitionmoreillonVerified publisher0.2.42 of 3See more

face-recognition moreillon 0.2.4

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
moreillon/face-recognition-fastapi:x86bacb2ddd8394
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

8,556
mqtt-loggermoreillonVerified publisher0.3.13 of 5See more

mqtt-logger moreillon 0.3.1

3 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16

Open the chart page →

10,959
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

25,704
multusmultusVerified publisher0.2.01 of 2See more

multus multus 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

1,852
hello-wordmuraig-hello-word0.2.21 of 1See more

hello-word muraig-hello-word 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.24.0f6daac2445b0
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

532
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

9,149
Practica_4_helmmy-heml-appVerified publisher0.1.02 of 7See more

Practica_4_helm my-heml-app 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
codeurjc/weatherservice:v1.0b9e2f7234349
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

27,721
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

9,542
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
pecan/web:1.7.2814d678c5550
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

14,154
smilencsaVerified publisher1.1.09 of 23See more

smile ncsa 1.1.0

9 of the 23 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/classification_split:0.1.24bfda60829fe
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/classification_train:0.1.207477060bba8
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_list:0.1.051cb17626519
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16

Open the chart page →

109,294
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,982
neuralbank-stackneuralbank-stack0.1.02 of 4See more

neuralbank-stack neuralbank-stack 0.1.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

5,191
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

7,310
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,843
nfl-walletnfl-walletVerified publisher0.1.33 of 4See more

nfl-wallet nfl-wallet 0.1.3

3 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9

Open the chart page →

13,041
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

7,035
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

3,419
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

1,902
liquidsoapnorth141.0.01 of 1See more

liquidsoap north14 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

2,954
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,422
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,875
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

4,547
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

5,873
lensoci-ai-incubations0.1.143 of 16See more

lens oci-ai-incubations 0.1.14

3 of the 16 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
curl@8.14.1-r0
8.14.1-r2
grafana/grafana:12.1.1a1701c218024
curl@8.14.1-r1
8.14.1-r2
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

17,070
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2

Open the chart page →

1,563
managed-serviceaccountocm-helm-chartsVerified publisher0.10.01 of 1See more

managed-serviceaccount ocm-helm-charts 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/managed-serviceaccount:v0.10.0d6284bd7765a
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,033
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,540
apicurioone-acre-fundVerified publisher2.3.04 of 5See more

apicurio one-acre-fund 2.3.0

4 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

18,667
one-green-coreone-green-coreVerified publisher0.0.71 of 8See more

one-green-core one-green-core 0.0.7

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/telegraf:1.20.428e98eece020
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

9,558
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

18,023
voltha-infraopencord2.14.01 of 10See more

voltha-infra opencord 2.14.0

1 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

41,044
openldapopenldap0.1.11 of 2See more

openldap openldap 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

7,459
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,796
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

2,370
bpjstk-serviceopenshift1.0.03 of 6See more

bpjstk-service openshift 1.0.0

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
andrianrf/backoffice-be:latest6036614803d4
curl@7.76.1-23.el9_2.1
0:7.76.1-23.el9_2.8
andrianrf/iso-server:latest7da47f525c7d
curl@7.76.1-23.el9_2.1
0:7.76.1-23.el9_2.8

Open the chart page →

34,671
canvas-oamportalopenshift4.0.01 of 1See more

canvas-oamportal openshift 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/oam:4.0.0ed8fd2062548
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9

Open the chart page →

7,519
chatbot-ai-sampleopenshift0.1.62 of 4See more

chatbot-ai-sample openshift 0.1.6

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ai-lab/llamacpp_python:latest70d138997acd
curl@7.76.1-29.el9_4.1
0:7.76.1-29.el9_4.3
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3

Open the chart page →

18,922
exporteropenshift1.0.473 of 3See more

exporter openshift 1.0.47

3 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

13,000
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.66 of 6See more

fsm openshift 0.1.8-ubi.6

6 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9

Open the chart page →

16,556
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3

Open the chart page →

4,127
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
curl@7.61.1-18.el8_4.2
0:7.61.1-34.el8_10.9
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi87 of 7See more

osm-edge openshift 1.2.1-ubi8

7 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9

Open the chart page →

19,455
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,063
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
curl@7.76.1-23.el9_2.2
0:7.76.1-23.el9_2.8

Open the chart page →

8,599
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,738

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
penpotapp/frontend:2.2.18974882a0542
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2
1
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
curl@7.76.1-26.el9_3.2
0:7.76.1-35.el9_7.3
1
phntom/binaryvision-tlo-static:0.0.4e8b9ac93a3dd
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
phntom/email-manager:0.1.22d8e2a9f2f085
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
phntom/external-dns-host-network:0.0.123adadbac8443
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
phntom/mattermost-defaultbackend:6.4.0c318dc90a4bf
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
photoprism/photoprism:251130db16ee6b1ba3
curl@8.14.1-2ubuntu1
8.14.1-2ubuntu1.1
1
phpmyadmin/phpmyadmin:5.138437e021deb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
curl@8.14.1-2
8.14.1-2+deb13u1
1
pihole/pihole:2023.05.0b83258064f54
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
curl@7.61.1-11.el8
0:7.61.1-34.el8_10.9
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
prodrigestivill/postgres-backup-local:latestf70742ebe42b
curl@8.14.1-2
8.14.1-2+deb13u1
1
ptthanh1511/daloradius:1.2-devafecc5143fcb
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
razzy10/product-service:latest702e411956db
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2
1
remche/shinyproxy:2.6.18bcda8a04d3b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
rm3l/dev-feed-api:latest9a7f732245a3
curl@7.76.1-23.el9_2.4
0:7.76.1-23.el9_2.8
1
rm3l/mac-oui:1.8.03a5e1f95c132
curl@7.61.1-33.el8_9.5
0:7.61.1-34.el8_10.9
1
robmarkcole/deepstack-ui:latest410275726459
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
robotshop/rs-dispatch:latestde81f1d07b02
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
robotshop/rs-payment:latest774b52c6180d
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
robotshop/rs-ratings:latest4899c686c249
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
robotshop/rs-shipping:latest89753ab48919
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
salehmir/jesse:1.10.101afa95f979e9
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
1
sarwansharma/minio:v359d1da9385d1
curl@7.61.1-22.el8_6.3
0:7.61.1-34.el8_10.9
1
seataio/seata-server:latest703b5de7f1a6
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
curl@7.61.1-18.el8_4.1
0:7.61.1-34.el8_10.9
1
seyiogunniran/my-nginx:1.03a0ed39e5830
curl@8.14.1-r1
8.14.1-r2
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
simpleidserver/faaswebsite:0.0.4367218ae760f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
socialmediamacroscope/classification_train:0.1.207477060bba8
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
1
sonatype/nexus3:3.58.1586060431b64
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9
1
sosedoff/pgweb:latesta5256d416e2e
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
1
speckle/speckle-frontend:2.18.11-branch.testing2.88634-335d46982c052441110
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.