StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,787 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,787 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
velero-notificationsvelero-notifications1.1.01 of 1See more

velero-notifications velero-notifications 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,285
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,392
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,262
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,262
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

2,132
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,552
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,138
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
curl@8.14.1-r0
8.14.1-r2
temporalio/server:1.29.1c1e3326b2ce1
curl@8.14.1-r0
8.14.1-r2
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

14,983
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,585
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

2,021
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,577
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

3,697

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gradiant/open5gs:2.7.575277742fc8a
curl@7.74.0-1.3+deb11u14
7.74.0-1.3+deb11u16
16
codeurjc/weatherservice:v1.0b9e2f7234349
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
10
codeurjc/server:v1.0310bea5b1ee7
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
8
wurstmeister/kafka:latest2d4bbf9cc83d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
6
library/nginx:1.21:1.21.62bcabc23b454
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
6
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
4
mastercloudapps/server:v2.23f3d24dfe2686
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
4
mastercloudapps/weatherservice:v1.23de859d29c116
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
4
quay.io/strimzi/operator:0.37.052f376e64b9b
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
4
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
3
library/influxdb:1.8:1.8.10299ebda2c7e3
curl@7.74.0-1.3+deb11u13
7.74.0-1.3+deb11u16
3
library/solr:8.11.18c5f7881cebb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
3
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
3
signoz/zookeeper:3.7.1fcc4a3288154
curl@7.74.0-1.3+deb11u9
7.74.0-1.3+deb11u16
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u16
3
quay.io/devtron/clair:4.3.675fb847ac045
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
curl@7.61.1-22.el8_6.9
0:7.61.1-34.el8_10.9
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
2
assistiot/fl_repository_db:latestad8f72108636
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9
2
confluentinc/cp-zookeeper:latest7610a50b13e7
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9
2
ilum/mongodb:6.0.542b6d774c37d
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
2
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
2
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
2
library/nginx:1.24.0f6daac2445b0
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
2
minio/operator:v4.3.754393e03f3b2
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
2
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
2
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
curl@7.61.1-22.el8_6.3
0:7.61.1-34.el8_10.9
2
vaultwarden/server:1.25.239f34c5159a2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
2
yzhou442/equiz:latesta3f7ca69e28d
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
curl@8.14.1-r1
8.14.1-r2
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
curl@8.14.1-r0
8.14.1-r2
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.