StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
570
of 17,781 indexed, latest versions
Container images
625
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 570 of 17,781 indexed charts deploy, on 625 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1286
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r234
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more305
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

570 by stars
ChartLatestAffected imagesRadar Score
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

10,061
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

8,032
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
adolfintel/speedtest:latest1f828fe83374
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,152
block-buster-helm-appbb-app-helm-chartsVerified publisher7.6.21 of 1See more

block-buster-helm-app bb-app-helm-charts 7.6.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,342
block-buster-helm-appblockbaster-helmapp7.6.01 of 1See more

block-buster-helm-app blockbaster-helmapp 7.6.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

977
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

2,507
phpcamptocamp31.0.01 of 1See more

php camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/php:7.3-apacheb9872cd287ef
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,309
mongodb-operatorccowleyVerified publisher0.1.11 of 1See more

mongodb-operator ccowley 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
curl@7.61.1-14.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,389
cert-utils-operatorcert-utils-operator1.3.122 of 2See more

cert-utils-operator cert-utils-operator 1.3.12

2 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,776
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,338
chart-appchart-app0.3.01 of 2See more

chart-app chart-app 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
n22107670/sample-app:0.4.08f3072db7aeb
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,775
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16
countly/frontend:25.05.42acbc11499b6
curl@7.74.0-1.3+deb11u12
7.74.0-1.3+deb11u16

Open the chart page →

7,295
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

1,423
clairclair-helmVerified publisher0.12.01 of 3See more

clair clair-helm 0.12.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/projectquay/clair:4.9.023329c3368e4
curl@7.61.1-34.el8_10.8
0:7.61.1-34.el8_10.9

Open the chart page →

1,617
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

20,900
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9

Open the chart page →

25,151
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.14 of 12See more

robot-shop cloud-native-toolkit 1.1.1

4 of the 12 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-payment:latest774b52c6180d
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-ratings:latest4899c686c249
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
robotshop/rs-shipping:latest89753ab48919
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

29,555
default-chartcnieg3.0.81 of 1See more

default-chart cnieg 3.0.8

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23.2ab589a3c466e
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

915
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9

Open the chart page →

19,338
ms-basecodedesignplus-chartsVerified publisher0.0.321 of 1See more

ms-base codedesignplus-charts 0.0.32

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
nginxdemos/hello:0.4b28d1e16c676
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,291
sumoconsensys0.4.1451 of 4See more

sumo consensys 0.4.145

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

5,958
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.11 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aidasi/swpspa:v1-1-net6-k8s-test-betadee4ec566312
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

10,091
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

1,797
cp-helm-chartscp-helm-charts0.6.17 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

7 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
confluentinc/cp-zookeeper:6.1.078c190f4472c
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

58,857
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
opencsghq/csgship-agentic:v0.4.02cd29671a03e
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
curl@7.74.0-1.3+deb11u15
7.74.0-1.3+deb11u16

Open the chart page →

11,335
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

5,293
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
aristidetm/k8s-hub:3.3.7ccb516cb8474
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16

Open the chart page →

16,604
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2

Open the chart page →

3,547
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

7,486
symfony-appdefault-ghVerified publisher0.6.51 of 3See more

symfony-app default-gh 0.6.5

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/nginx:1.23f5747a42e3ad
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

5,122
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
curl@7.76.1-29.el9_4.1
0:7.76.1-35.el9_7.3

Open the chart page →

3,191
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

29,033
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

12,992
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,237
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

7,459
nova-exporterdjjudas21Verified publisher0.1.161 of 1See more

nova-exporter djjudas21 0.1.16

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
djjudas21/nova-exporter:0.0.10e9094580885c
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,411
truecommanddjjudas21Verified publisher0.1.01 of 1See more

truecommand djjudas21 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ixsystems/truecommand:3.2.019c218455cd2
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

5,174
dnation-kubernetes-monitoring-stackdnationcloud4.0.22 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

2 of the 17 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

21,641
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3

Open the chart page →

3,167
helpdeskdoubanVerified publisher0.3.31 of 2See more

helpdesk douban 0.3.3

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
douz/helpdesk:latest4384103d0219
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16

Open the chart page →

4,550
tinyproxy-exporterdoubanVerified publisher0.1.21 of 1See more

tinyproxy-exporter douban 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16

Open the chart page →

3,421
drogue-cloud-coredrogue-iotVerified publisher0.7.1120 of 22See more

drogue-cloud-core drogue-iot 0.7.11

20 of the 22 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
curl@7.76.1-19.el9
0:7.76.1-35.el9_7.3
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

55,666
drogue-cloud-examplesdrogue-iotVerified publisher0.7.113 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

3 of the 6 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ctron/kubectl:1.25e37d61b5277c
curl@7.61.1-33.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

30,699
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
pgdump-to-s3duck-helm0.1.41 of 1See more

pgdump-to-s3 duck-helm 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,362
postgres-backup-localduck-helm0.1.51 of 1See more

postgres-backup-local duck-helm 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:latestf70742ebe42b
curl@8.14.1-2
8.14.1-2+deb13u1

Open the chart page →

3,455

Container images carrying it

625 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gradiant/open5gs:2.7.575277742fc8a
curl@7.74.0-1.3+deb11u14
7.74.0-1.3+deb11u16
16
codeurjc/weatherservice:v1.0b9e2f7234349
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
10
codeurjc/server:v1.0310bea5b1ee7
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
8
wurstmeister/kafka:latest2d4bbf9cc83d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
6
library/nginx:1.21:1.21.62bcabc23b454
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
6
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
4
mastercloudapps/server:v2.23f3d24dfe2686
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
4
mastercloudapps/weatherservice:v1.23de859d29c116
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
4
quay.io/strimzi/operator:0.37.052f376e64b9b
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
4
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
3
library/influxdb:1.8:1.8.10299ebda2c7e3
curl@7.74.0-1.3+deb11u13
7.74.0-1.3+deb11u16
3
library/solr:8.11.18c5f7881cebb
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9
3
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
3
siddharth67/block-buster-dev:7.6.04e1151ea5774
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
3
signoz/zookeeper:3.7.1fcc4a3288154
curl@7.74.0-1.3+deb11u9
7.74.0-1.3+deb11u16
3
gcr.io/trillian-opensource-ci/db_server2a685a38dd01
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u16
3
quay.io/devtron/clair:4.3.675fb847ac045
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
curl@7.61.1-22.el8_6.9
0:7.61.1-34.el8_10.9
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
3
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
2
assistiot/fl_repository_db:latestad8f72108636
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
curl@7.74.0-1.3+deb11u5
7.74.0-1.3+deb11u16
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9
2
confluentinc/cp-zookeeper:latest7610a50b13e7
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
curl@7.61.1-30.el8_8.2
0:7.61.1-34.el8_10.9
2
ilum/mongodb:6.0.542b6d774c37d
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
2
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
2
ldapaccountmanager/lam:8.0.1d46cf25d1dda
curl@7.74.0-1.3+deb11u2
7.74.0-1.3+deb11u16
2
library/nginx:1.24.0f6daac2445b0
curl@7.74.0-1.3+deb11u11
7.74.0-1.3+deb11u16
2
minio/operator:v4.3.754393e03f3b2
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
2
pecan/bety:5.4.1f825d480cd62
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
2
postgis/postgis:15-3.3a2fc46b52819
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
curl@7.74.0-1.3+b1
7.74.0-1.3+deb11u16
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
curl@7.61.1-22.el8_6.3
0:7.61.1-34.el8_10.9
2
vaultwarden/server:1.25.239f34c5159a2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
2
yzhou442/equiz:latesta3f7ca69e28d
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
curl@8.14.1-r1
8.14.1-r2
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
curl@8.14.1-r1
8.14.1-r2
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
curl@8.14.1-r0
8.14.1-r2
2
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
2
quay.io/flomesh/curl-ubi8:7.84.0bef31fa5f5f3
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
2
quay.io/keycloak/keycloak:20.0054ef67eb7da
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.