StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

10,061
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,032
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
adolfintel/speedtest:latest1f828fe83374
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,152
block-buster-helm-appbb-app-helm-chartsVerified publisher7.6.21 of 1See more

block-buster-helm-app bb-app-helm-charts 7.6.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,342
block-buster-helm-appblockbaster-helmapp7.6.01 of 1See more

block-buster-helm-app blockbaster-helmapp 7.6.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

2,507
phpcamptocamp31.0.01 of 1See more

php camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/php:7.3-apacheb9872cd287ef
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,309
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
curl@7.61.1-14.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,389
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,776
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
n22107670/sample-app:0.4.08f3072db7aeb
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,775
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
countly/frontend:25.05.42acbc11499b6
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16

Open the chart page →

7,295
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,423
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
curl@7.61.1-34.el8_10.8
0:7.61.1-34.el8_10.9

Open the chart page →

1,617
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

20,900
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9

Open the chart page →

25,151
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.14 of 12See more

robot-shop cloud-native-toolkit 1.1.1

4 of the 12 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-payment:latest774b52c6180d
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-ratings:latest4899c686c249
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-shipping:latest89753ab48919
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

29,555
default-chartcnieg3.0.81 of 1See more

default-chart cnieg 3.0.8

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23.2ab589a3c466e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

915
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

19,338
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,291
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

5,958
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.11 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

10,091
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

1,797
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-zookeeper:6.1.078c190f4472c
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

58,857
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16

Open the chart page →

11,335
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aristidetm/k8s-hub:3.3.7ccb516cb8474
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

16,604
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

3,547
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,486
symfony-appdefault-ghVerified publisher0.6.51 of 3See more

symfony-app default-gh 0.6.5

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23f5747a42e3ad
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

5,122
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
curl@7.76.1-29.el9_4.1
0:7.76.1-35.el9_7.3

Open the chart page →

3,191
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

29,033
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

12,992
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,237
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

7,459
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,411
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

5,174
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

21,641
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

3,167
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

4,550
tinyproxy-exporterdoubanVerified publisher0.1.21 of 1See more

tinyproxy-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

3,421
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ctron/kubectl:1.25e37d61b5277c
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,362
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,455

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
speckle/speckle-frontend:2.18.12-branch.testing3.88744-f55b341d5f689c9256c
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
speckle/speckle-frontend:2.17.14-branch.testing.72707.921a5f8d9b58995a8b8
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
splunk/splunk-operator:2.0.0c4e0d3146226
curl@7.61.1-22.el8_6.3
0:7.61.1-34.el8_10.9
1
stakater/workshop-operator:v0.0.3897bf456cc97c
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
stratospire/activityrelay:0.2.3a4c34cb01117
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
supabase/logflare:1.8.12d429005429ce
curl@7.74.0-1.3+deb11u13
7.74.0-1.3+deb11u16
1
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
t3nde/tideways:1.7.2777e008f764db
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
tautulli/tautulli:v2.7.7c4da15f058ea
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
curl@8.14.1-r0
8.14.1-r2
1
temporalio/auto-setup:1.29.15b3502a3b685
curl@8.14.1-r0
8.14.1-r2
1
temporalio/server:1.29.1c1e3326b2ce1
curl@8.14.1-r0
8.14.1-r2
1
th0th/node-red:4.0.3-debiand06fa39f7406
curl@7.74.0-1.3+deb11u13
7.74.0-1.3+deb11u16
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
torrespro/mca-worker:2.0.06d3bd305a1ba
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
trinodb/trino:45038c6f24ab1a4
curl@7.76.1-29.el9_4
0:7.76.1-29.el9_4.3
1
trinodb/trino:4796af989b0846d
curl@8.12.1-2.el10
0:8.12.1-2.el10_1.2
1
udhos/token-server:1.0.9728013f2fac1
curl@8.14.1-r1
8.14.1-r2
1
uffizzi/app:latest66e9e3937c60
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
vaultwarden/server:1.29.1c2849f8189e4
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
vcnngr/pnfrontend:latest4e4979ab8c41
curl@8.14.1-r1
8.14.1-r2
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
1
vlebediantsev/config-server-another:lateste7f20450d2ae
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
vlebediantsev/logic-ms:latestdf8bf38c535b
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
vlebediantsev/registration-ms-final:latest427af418b75e
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
volkerraschek/postfixadmin:3.3.13c4f10aebf87b
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
xtrendence/cryptofolio:V.2.2.0e6e6612bb94c
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
curl@8.14.1-r1
8.14.1-r2
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
1
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
1
ghcr.io/0xemma/reddark:main2a115e991894
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2
1
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9
1
ghcr.io/b-it-projects-gmbh/nvme_exporter:lateste70307b193c6
curl@8.14.1-r0
8.14.1-r2
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
1
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.